CVE-2022-26143

The TP-240 (aka tp240dvr) component in Mitel MiCollab before 9.4 SP1 FP1 and MiVoice Business Express through 8.1 allows remote attackers to obtain sensitive information and cause a denial of service (performance degradation and excessive outbound traffic). This was exploited in the wild in February and March 2022 for the TP240PhoneHome DDoS attack.
Advertisement

NeevaHost hosting service

Configurations

Configuration 1 (hide)

OR cpe:2.3:a:mitel:micollab:*:*:*:*:*:-:*:*
cpe:2.3:a:mitel:micollab:9.4:-:*:*:*:-:*:*
cpe:2.3:a:mitel:micollab:9.4:sp1:*:*:*:-:*:*
cpe:2.3:a:mitel:mivoice_business_express:*:*:*:*:*:*:*:*

Information

Published : 2022-03-10 09:47

Updated : 2022-03-18 12:52


NVD link : CVE-2022-26143

Mitre link : CVE-2022-26143


JSON object : View

CWE
CWE-863

Incorrect Authorization

Advertisement

dedicated server usa

Products Affected

mitel

  • micollab
  • mivoice_business_express