Lucene search

K
cvelistMitreCVELIST:CVE-2022-26143
HistoryMar 09, 2022 - 3:32 p.m.

CVE-2022-26143

2022-03-0915:32:54
mitre
www.cve.org
4
mitel
micollab
mivoice business express
tp-240
vulnerability
remote attackers
sensitive information
denial of service
ddos attack

AI Score

9.4

Confidence

High

EPSS

0.059

Percentile

93.5%

The TP-240 (aka tp240dvr) component in Mitel MiCollab before 9.4 SP1 FP1 and MiVoice Business Express through 8.1 allows remote attackers to obtain sensitive information and cause a denial of service (performance degradation and excessive outbound traffic). This was exploited in the wild in February and March 2022 for the TP240PhoneHome DDoS attack.

AI Score

9.4

Confidence

High

EPSS

0.059

Percentile

93.5%