Lucene search

K
cveMitreCVE-2022-26143
HistoryMar 10, 2022 - 5:47 p.m.

CVE-2022-26143

2022-03-1017:47:32
CWE-306
mitre
web.nvd.nist.gov
934
In Wild
2
mitel
micollab
tp-240
cve-2022-26143
security vulnerability
ddos攻击
information disclosure

CVSS2

9

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:P/I:P/A:C

CVSS3

9.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

AI Score

9.1

Confidence

High

EPSS

0.059

Percentile

93.5%

The TP-240 (aka tp240dvr) component in Mitel MiCollab before 9.4 SP1 FP1 and MiVoice Business Express through 8.1 allows remote attackers to obtain sensitive information and cause a denial of service (performance degradation and excessive outbound traffic). This was exploited in the wild in February and March 2022 for the TP240PhoneHome DDoS attack.

Affected configurations

Nvd
Node
mitelmicollabRange<9.4-
OR
mitelmicollabMatch9.4--
OR
mitelmicollabMatch9.4sp1-
OR
mitelmivoice_business_expressRange8.1
VendorProductVersionCPE
mitelmicollab*cpe:2.3:a:mitel:micollab:*:*:*:*:*:-:*:*
mitelmicollab9.4cpe:2.3:a:mitel:micollab:9.4:-:*:*:*:-:*:*
mitelmicollab9.4cpe:2.3:a:mitel:micollab:9.4:sp1:*:*:*:-:*:*
mitelmivoice_business_express*cpe:2.3:a:mitel:mivoice_business_express:*:*:*:*:*:*:*:*

Social References

More

CVSS2

9

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:P/I:P/A:C

CVSS3

9.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

AI Score

9.1

Confidence

High

EPSS

0.059

Percentile

93.5%