CVE-2022-26143
MiCollab, MiVoice Business Express Access Control Vulnerability
Does this matter?
Known to be exploited in the wild (CISA KEV, CISA remediation deadline 15 April 2022). Treat as an emergency change: patch or isolate now, then hunt for prior compromise.
Description
The TP-240 (aka tp240dvr) component in Mitel MiCollab before 9.4 SP1 FP1 and MiVoice Business Express through 8.1 allows remote attackers to obtain sensitive information and cause a denial of service (performance degradation and excessive outbound traffic). This was exploited in the wild in February and March 2022 for the TP240PhoneHome DDoS attack.
- CVSS 3.1
- 9.8 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 87.21% probability · 100th percentile
- CISA KEV
- Listed 25 March 2022 · due 15 April 2022
- Weakness
- CWE-306
- Affected
- mitel/micollab · mitel/mivoice business express
- Source
- cve@mitre.org
CISA notes
Apply updates per vendor instructions. https://nvd.nist.gov/vuln/detail/CVE-2022-26143
References
- https://arstechnica.com/information-technology/2022/03/ddosers-use-new-method-capable-of-amplifying-traffic-by-a-factor-of-4-billion/Exploit, Press/Media Coverage, Third Party Advisory
- https://blog.cloudflare.com/cve-2022-26143/Mitigation, Third Party Advisory
- https://news.ycombinator.com/item?id=30614073Issue Tracking, Third Party Advisory
- https://team-cymru.com/blog/2022/03/08/record-breaking-ddos-potential-discovered-cve-2022-26143/Broken Link, Mitigation, Third Party Advisory
- https://www.akamai.com/blog/security/phone-home-ddos-attack-vectorMitigation, Third Party Advisory
- https://www.mitel.com/en-ca/support/security-advisories/mitel-product-security-advisory-22-0001Vendor Advisory
- https://www.shadowserver.org/news/cve-2022-26143-tp240phonehome-reflection-amplification-ddos-attack-vector/Mitigation, Third Party Advisory
- https://arstechnica.com/information-technology/2022/03/ddosers-use-new-method-capable-of-amplifying-traffic-by-a-factor-of-4-billion/Exploit, Press/Media Coverage, Third Party Advisory
- https://blog.cloudflare.com/cve-2022-26143/Mitigation, Third Party Advisory
- https://news.ycombinator.com/item?id=30614073Issue Tracking, Third Party Advisory
- https://team-cymru.com/blog/2022/03/08/record-breaking-ddos-potential-discovered-cve-2022-26143/Broken Link, Mitigation, Third Party Advisory
- https://www.akamai.com/blog/security/phone-home-ddos-attack-vectorMitigation, Third Party Advisory
- https://www.mitel.com/en-ca/support/security-advisories/mitel-product-security-advisory-22-0001Vendor Advisory
- https://www.shadowserver.org/news/cve-2022-26143-tp240phonehome-reflection-amplification-ddos-attack-vector/Mitigation, Third Party Advisory
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2022-26143US Government Resource
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.