CVE-2022-26143
CRITICAL KEV NUCLEIMitel MiCollab - Information Disclosure & Denial of Service
Title source: nucleiDescription
The TP-240 (aka tp240dvr) component in Mitel MiCollab before 9.4 SP1 FP1 and MiVoice Business Express through 8.1 allows remote attackers to obtain sensitive information and cause a denial of service (performance degradation and excessive outbound traffic). This was exploited in the wild in February and March 2022 for the TP240PhoneHome DDoS attack.
Nuclei Templates (1)
Mitel MiCollab - Information Disclosure & Denial of Service
CRITICALVERIFIEDby theamanrawat
Shodan:
html:"MiCollab End User Portal"
References (8)
Scores
CVSS v3
9.8
EPSS
0.8915
EPSS Percentile
99.5%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Details
CISA KEV
2022-03-25
VulnCheck KEV
2022-03-08
InTheWild.io
2022-03-10
ENISA EUVD
EUVD-2022-30710
CWE
CWE-306
Status
published
Products (3)
mitel/micollab
9.4 (2 CPE variants)
mitel/micollab
< 9.4
mitel/mivoice_business_express
< 8.1
Published
Mar 10, 2022
KEV Added
Mar 25, 2022
Tracked Since
Feb 18, 2026