PRIOn Logo

CVE-2022-26143 Code injection

Urgent
Remediate Within one Week

CVE Information

Original CVE data

Published:
Updated:

The TP-240 (aka tp240dvr) component in Mitel MiCollab before 9.4 SP1 FP1 and MiVoice Business Express through 8.1 allows remote attackers to obtain sensitive information and cause a denial of service (performance degradation and excessive outbound traffic). This was exploited in the wild in February and March 2022 for the TP240PhoneHome DDoS attack.

CWE: CWE-306
CVSS v29
AV:N/AC:L/AU:N/C:P/I:P/A:C
CVSS v39.8
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
References
https://www.akamai.com/blog/security/phone-home-ddos-attack-vector
https://blog.cloudflare.com/cve-2022-26143/
https://team-cymru.com/blog/2022/03/08/record-breaking-ddos-potential-discovered-cve-2022-26143/
https://www.shadowserver.org/news/cve-2022-26143-tp240phonehome-reflection-amplification-ddos-attack-vector/
https://news.ycombinator.com/item?id=30614073
https://www.mitel.com/en-ca/support/security-advisories/mitel-product-security-advisory-22-0001
https://arstechnica.com/information-technology/2022/03/ddosers-use-new-method-capable-of-amplifying-traffic-by-a-factor-of-4-billion/
Affected Vendors

Mitel - (2)

Basic Analysis

Common vulnerability metrics

Vulnerabilty type as detected by PRIOnengine

Code injection

CVSS Scores as calculated by PRIOnengine
CVSS v25
AV:N/AC:L/AU:N/C:N/I:N/A:P
CVSS v39.1
AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H
MITRE CWE Top 25

Vulnerability weakness type is in the top 25 CWEs according to MITRE. View Mitre Top 25 CWEs

Exploits

No exploit code is reported to exist.

Active Exploitation

Vulnerability is referenced under CISA's Known Exploited Vulnerabilities (KEV) catalog. See the KEV Catalog

Social Network Activity

Vulnerability is mentioned or trending in social media.

Threat Actor Activity

Vulnerability is being actively exploited by threat actors during campaigns.

Cybersecurity Frameworks

How the vulnerability maps against various cybersecurity frameworks

T1591 - Gather Victim Org Information
T1590 - Gather Victim Network Information
T1589.001 - Gather Victim Identity Information (Credentials)
T1552 - Unsecured Credentials
T1499 - Endpoint Denial of Service
T1498 - Network Denial of Service
T1203 - Exploitation for Client Execution
T1082 - System Information Discovery
T1059 - Command and Scripting Interpreter
T1003 - OS Credential Dumping

Compliance Impact

How the submited vulnerability affects compliance

PCI DSS v3.2.1-6.5.5 - Improper Error Handling

Web Application Security Frameworks

Applicable if the issue likely affects a web application

-