Vulnerability record · CVE-2022-26143 · published 10 March 2022
CVE-2022-26143: Mitel MiCollab TP-240 missing authentication enables DDoS and data exposure
Mitel · Micollab
The TP-240 (tp240dvr) component in Mitel MiCollab before 9.4 SP1 FP1 and MiVoice Business Express through 8.1 lacks authentication for a critical function, allowing remote attackers to obtain sensitive information and cause performance degradation with excessive outbound traffic. It was exploited in the wild in February and March 2022 as the TP240PhoneHome reflection/amplification DDoS vector.
Description
The TP-240 (aka tp240dvr) component in Mitel MiCollab before 9.4 SP1 FP1 and MiVoice Business Express through 8.1 allows remote attackers to obtain sensitive information and cause a denial of service (performance degradation and excessive outbound traffic). This was exploited in the wild in February and March 2022 for the TP240PhoneHome DDoS attack.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityCVSS 9.8, CISA KEV listing with confirmed in-the-wild exploitation, and very high EPSS probability make this an urgent patch.
What it is
The TP-240 (tp240dvr) component in Mitel MiCollab before 9.4 SP1 FP1 and MiVoice Business Express through 8.1 lacks authentication for a critical function, allowing remote attackers to obtain sensitive information and cause performance degradation with excessive outbound traffic. It was exploited in the wild in February and March 2022 as the TP240PhoneHome reflection/amplification DDoS vector.
Impact
An attacker can read sensitive information from the exposed service and abuse it to generate large volumes of outbound traffic, degrading performance and enabling high-amplification DDoS against third parties.
Attack surface
Reachable over the network with no authentication and no user interaction required, per the CVSS vector AV:N/AC:L/PR:N/UI:N. Any internet-exposed TP-240 service is directly usable.
Exploitation
Listed in CISA KEV (added 2022-03-25) with confirmed in-the-wild exploitation in February and March 2022, and EPSS 30-day probability is 0.87212 (99.7th percentile). Reference tags include Exploit and multiple mitigation advisories.
What to do
- Apply the vendor update per Mitel advisory 22-0001 (MiCollab 9.4 SP1 FP1 or later; MiVoice Business Express beyond 8.1).
- Remove or block internet exposure of the TP-240/tp240dvr service until patched.
- Restrict access to the service with firewall rules and network segmentation.
- Monitor and rate-limit outbound traffic from affected hosts to limit amplification abuse.
- Follow CISA KEV required action and confirm remediation by the 2022-04-15 due date.
Detection
- Monitor for anomalous outbound traffic volume or amplification patterns from MiCollab/MiVoice hosts.
- Alert on unexpected inbound requests to the TP-240 service port from external sources.
- Review logs for unauthenticated access to the tp240dvr component.
- Track exposure of affected hosts via external attack-surface scans.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2022-26143 to the Known Exploited Vulnerabilities catalog on 25 March 2022 as "MiCollab, MiVoice Business Express Access Control Vulnerability". Required action: Apply updates per vendor instructions. Federal deadline 15 April 2022.
Affected products
2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2022-26143 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2022-26143), CISA KEV, FIRST EPSS (scores of 2026-09-24). This page is refreshed as NVD updates the record.