CVE-2022-26143
About
The TP-240 (aka tp240dvr) component in Mitel MiCollab before 9.4 SP1 FP1 and MiVoice Business Express through 8.1 allows remote attackers to obtain sensitive information and cause a denial of service (performance degradation and excessive outbound traffic). This was exploited in the wild in February and March 2022 for the TP240PhoneHome DDoS attack.
Rainforest analyst review
The TP-240 (tp240dvr) audio component in Mitel MiCollab and MiVoice Business Express exposes a diagnostic UDP command interface with no authentication. A single small request causes the service to emit a large volume of response traffic, and a specific test command can be abused to generate an enormous, sustained flood. Because the source address on UDP is trivially spoofed, an attacker directs that amplified traffic at a victim of their choosing, turning each exposed Mitel appliance into a reflector.
This is the flaw behind the TP240PhoneHome campaign of early 2022, notable for an amplification ratio among the highest ever recorded, which let a handful of exposed systems produce record-scale reflection DDoS. The exposure here is dual: the organization running the vulnerable PBX becomes an unwitting weapon against third parties and suffers performance degradation and outbound bandwidth exhaustion itself. Only a few thousand systems were ever exposed, which made cleanup tractable but also made each one disproportionately dangerous. Apply Mitel's fix, and in the meantime block the affected UDP port at the network edge so the diagnostic interface is unreachable from the internet.
References
- https://arstechnica.com/information-technology/2022/03/ddosers-use-new-method-capable-of-amplifying-traffic-by-a-factor-of-4-billion/
- https://blog.cloudflare.com/cve-2022-26143/
- https://news.ycombinator.com/item?id=30614073
- https://team-cymru.com/blog/2022/03/08/record-breaking-ddos-potential-discovered-cve-2022-26143/
- https://www.akamai.com/blog/security/phone-home-ddos-attack-vector
- https://www.mitel.com/en-ca/support/security-advisories/mitel-product-security-advisory-22-0001
- https://www.shadowserver.org/news/cve-2022-26143-tp240phonehome-reflection-amplification-ddos-attack-vector/
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2022-26143
Related CVEs
Frequently asked questions
What is CVE-2022-26143?
The TP-240 (aka tp240dvr) component in Mitel MiCollab before 9.4 SP1 FP1 and MiVoice Business Express through 8.1 allows remote attackers to obtain sensitive information and cause a denial of service (performance degradation and excessive outbound traffic). This was exploited in the wild in February and March 2022 for the TP240PhoneHome DDoS attack.
How severe is CVE-2022-26143?
CVE-2022-26143 carries a CVSS 3.1 base score of 9.8, rated critical. On the Rainforest Risk Index — which weighs the severity alongside how easy the flaw is to reach and how broad its impact is — it scores 99 out of 100, in the critical band.
How is CVE-2022-26143 exploited?
According to the CVSS vector (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H): attack vector Network, attack complexity Low, privileges required None, user interaction None. Impact on confidentiality High, integrity High and availability High.
Which products are affected by CVE-2022-26143?
Public advisories list the following as affected: micollab, mivoice business express. Check the references on this page for the exact versions each vendor confirms.
How do I fix CVE-2022-26143?
Apply the fix the vendor published — the references on this page link to the primary advisories and patches. When patching can't happen right away, reduce the exposure of the affected component and watch it for exploitation attempts. Rainforest customers see this vulnerability correlated to their own assets and prioritized by real exposure, not by score alone.
Empower Your Security Strategy with Rainforest
Discover vulnerabilities early, prioritize critical threats, and protect what truly matters. Rainforest streamlines your security operations, saving you time and reducing costs, so you can focus on what drives your business forward.
