9.8

CVE-2022-26143

Warnung
Medienbericht
Exploit
The TP-240 (aka tp240dvr) component in Mitel MiCollab before 9.4 SP1 FP1 and MiVoice Business Express through 8.1 allows remote attackers to obtain sensitive information and cause a denial of service (performance degradation and excessive outbound traffic). This was exploited in the wild in February and March 2022 for the TP240PhoneHome DDoS attack.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
MitelMicollab SwPlatform- Version < 9.4
MitelMicollab Version9.4 Update- SwPlatform-
MitelMicollab Version9.4 Updatesp1 SwPlatform-
MitelMivoice Business Express Version <= 8.1

25.03.2022: CISA Known Exploited Vulnerabilities (KEV) Catalog

MiCollab, MiVoice Business Express Access Control Vulnerability

Schwachstelle

A vulnerability has been identified in MiCollab and MiVoice Business Express that may allow a malicious actor to gain unauthorized access to sensitive information and services, cause performance degradations or a denial of service condition on the affected system.

Beschreibung

Apply updates per vendor instructions.

Erforderliche Maßnahmen
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 87.57% 0.997
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 9.8 3.9 5.9
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvd@nist.gov 9 10 8.5
AV:N/AC:L/Au:N/C:P/I:P/A:C
134c704f-9b21-4f2e-91b3-4a467353bcc0 9.8 3.9 5.9
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CWE-306 Missing Authentication for Critical Function

The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.

https://arstechnica.com/information-technology/2022/03/ddosers-use-new-method-capable-of-amplifying-traffic-by-a-factor-of-4-billion/
Third Party Advisory
Exploit
Press/Media Coverage
https://blog.cloudflare.com/cve-2022-26143/
Third Party Advisory
Mitigation
https://news.ycombinator.com/item?id=30614073
Third Party Advisory
Issue Tracking
https://team-cymru.com/blog/2022/03/08/record-breaking-ddos-potential-discovered-cve-2022-26143/
Third Party Advisory
Broken Link
Mitigation
https://www.akamai.com/blog/security/phone-home-ddos-attack-vector
Third Party Advisory
Mitigation
https://www.mitel.com/en-ca/support/security-advisories/mitel-product-security-advisory-22-0001
Vendor Advisory
https://www.shadowserver.org/news/cve-2022-26143-tp240phonehome-reflection-amplification-ddos-attack-vector/
Third Party Advisory
Mitigation
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2022-26143
US Government Resource