TROYANOSYVIRUS
Zuruck zu CVEs

CVE-2022-26143

CRITICALCISA KEV
9.8

Beschreibung

The TP-240 (aka tp240dvr) component in Mitel MiCollab before 9.4 SP1 FP1 and MiVoice Business Express through 8.1 allows remote attackers to obtain sensitive information and cause a denial of service (performance degradation and excessive outbound traffic). This was exploited in the wild in February and March 2022 for the TP240PhoneHome DDoS attack.

CVE Details

CVSS v3.1 Bewertung9.8
SchweregradCRITICAL
CVSS VektorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
AngriffsvektorNETWORK
KomplexitatLOW
Erforderliche PrivilegienNONE
BenutzerinteraktionNONE
Veroffentlicht3/10/2022
Zuletzt geandert11/3/2025
Quellekev
Honeypot-Sichtungen0

CISA KEV

HerstellerMitel
ProduktMiCollab, MiVoice Business Express
SchwachstellennameMiCollab, MiVoice Business Express Access Control Vulnerability
KEV Aufnahmedatum2022-03-25
Behebungsfrist2022-04-15
Ransomware-NutzungUnknown

Betroffene Produkte

mitel:micollabmitel:mivoice_business_express

Schwachen (CWE)

CWE-306CWE-306

Referenzen

https://blog.cloudflare.com/cve-2022-26143/(af854a3a-2127-422b-91ae-364da2661108)
https://news.ycombinator.com/item?id=30614073(af854a3a-2127-422b-91ae-364da2661108)

IOC Korrelationen

Keine Korrelationen erfasst

This product uses data from the NVD API but is not endorsed or certified by the NVD.