← Vulnerability feed

Vulnerability record · CVE-2022-26143 · published 10 March 2022

CVE-2022-26143: Mitel MiCollab TP-240 missing authentication enables DDoS and data exposure

Mitel · Micollab

The TP-240 (tp240dvr) component in Mitel MiCollab before 9.4 SP1 FP1 and MiVoice Business Express through 8.1 lacks authentication for a critical function, allowing remote attackers to obtain sensitive information and cause performance degradation with excessive outbound traffic. It was exploited in the wild in February and March 2022 as the TP240PhoneHome reflection/amplification DDoS vector.

9.8 CVSS 3.1 Critical CISA KEV since 25 Mar 2022 EPSS 87% · top 0.2% CWE-306 · Missing authentication for critical function
9.8CVSS 3.1 base score, v2 9.0
87%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
2Affected product versions listed by NVD
15References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

The TP-240 (aka tp240dvr) component in Mitel MiCollab before 9.4 SP1 FP1 and MiVoice Business Express through 8.1 allows remote attackers to obtain sensitive information and cause a denial of service (performance degradation and excessive outbound traffic). This was exploited in the wild in February and March 2022 for the TP240PhoneHome DDoS attack.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 17 September 2026. Confidence: high.

critical priorityCVSS 9.8, CISA KEV listing with confirmed in-the-wild exploitation, and very high EPSS probability make this an urgent patch.

What it is

The TP-240 (tp240dvr) component in Mitel MiCollab before 9.4 SP1 FP1 and MiVoice Business Express through 8.1 lacks authentication for a critical function, allowing remote attackers to obtain sensitive information and cause performance degradation with excessive outbound traffic. It was exploited in the wild in February and March 2022 as the TP240PhoneHome reflection/amplification DDoS vector.

Impact

An attacker can read sensitive information from the exposed service and abuse it to generate large volumes of outbound traffic, degrading performance and enabling high-amplification DDoS against third parties.

Attack surface

Reachable over the network with no authentication and no user interaction required, per the CVSS vector AV:N/AC:L/PR:N/UI:N. Any internet-exposed TP-240 service is directly usable.

Exploitation

Listed in CISA KEV (added 2022-03-25) with confirmed in-the-wild exploitation in February and March 2022, and EPSS 30-day probability is 0.87212 (99.7th percentile). Reference tags include Exploit and multiple mitigation advisories.

What to do

  • Apply the vendor update per Mitel advisory 22-0001 (MiCollab 9.4 SP1 FP1 or later; MiVoice Business Express beyond 8.1).
  • Remove or block internet exposure of the TP-240/tp240dvr service until patched.
  • Restrict access to the service with firewall rules and network segmentation.
  • Monitor and rate-limit outbound traffic from affected hosts to limit amplification abuse.
  • Follow CISA KEV required action and confirm remediation by the 2022-04-15 due date.

Detection

  • Monitor for anomalous outbound traffic volume or amplification patterns from MiCollab/MiVoice hosts.
  • Alert on unexpected inbound requests to the TP-240 service port from external sources.
  • Review logs for unauthenticated access to the tp240dvr component.
  • Track exposure of affected hosts via external attack-surface scans.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2022-26143 to the Known Exploited Vulnerabilities catalog on 25 March 2022 as "MiCollab, MiVoice Business Express Access Control Vulnerability". Required action: Apply updates per vendor instructions. Federal deadline 15 April 2022.

Affected products

2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
https://arstechnica.com/information-technology/2022/03/ddosers-use-new-method-capable-of-amplifying-traffic-by-a-factor- ExploitPress/Media CoverageThird Party Advisory
https://blog.cloudflare.com/cve-2022-26143/ MitigationThird Party Advisory
https://news.ycombinator.com/item?id=30614073 Issue TrackingThird Party Advisory
https://team-cymru.com/blog/2022/03/08/record-breaking-ddos-potential-discovered-cve-2022-26143/ Broken LinkMitigationThird Party Advisory
https://www.akamai.com/blog/security/phone-home-ddos-attack-vector MitigationThird Party Advisory
https://www.mitel.com/en-ca/support/security-advisories/mitel-product-security-advisory-22-0001 Vendor Advisory
https://www.shadowserver.org/news/cve-2022-26143-tp240phonehome-reflection-amplification-ddos-attack-vector/ MitigationThird Party Advisory
https://arstechnica.com/information-technology/2022/03/ddosers-use-new-method-capable-of-amplifying-traffic-by-a-factor- ExploitPress/Media CoverageThird Party Advisory
https://blog.cloudflare.com/cve-2022-26143/ MitigationThird Party Advisory
https://news.ycombinator.com/item?id=30614073 Issue TrackingThird Party Advisory
https://team-cymru.com/blog/2022/03/08/record-breaking-ddos-potential-discovered-cve-2022-26143/ Broken LinkMitigationThird Party Advisory
https://www.akamai.com/blog/security/phone-home-ddos-attack-vector MitigationThird Party Advisory
https://www.mitel.com/en-ca/support/security-advisories/mitel-product-security-advisory-22-0001 Vendor Advisory
https://www.shadowserver.org/news/cve-2022-26143-tp240phonehome-reflection-amplification-ddos-attack-vector/ MitigationThird Party Advisory
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2022-26143 US Government Resource

Track CVE-2022-26143 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.1CVE-2024-41713Mitel MiCollab NuPoint path traversal allows unauthenticated file accessMitel MiCollab's NuPoint Unified Messaging component fails to validate input, allowing a path traversal attack through version 9.8 SP1 FP2 (9.8.1.201…KEVEPSS 98%analysed7.5CVE-2014-0160OpenSSL TLS/DTLS Heartbeat Extension Out-of-Bounds Read (Heartbleed)OpenSSL 1.0.1 before 1.0.1g mishandles Heartbeat Extension packets in its TLS and DTLS implementations, causing an out-of-bounds read of process memo…KEVEPSS 100%analysed2.7CVE-2024-55550Mitel MiCollab path traversal allows admin local file readMitel MiCollab through 9.8 SP2 has a path traversal flaw (CWE-22) caused by insufficient input sanitization. An authenticated attacker with administr…KEVEPSS 38%analysed9.8CVE-2024-35285Mitel micollab command injection vulnerabilityA vulnerability in NuPoint Messenger (NPM) of Mitel MiCollab through 9.8.0.33 allows an unauthenticated attacker to conduct a command injection attac…EPSS 1.3%9.8CVE-2024-35286Mitel MiCollab NuPoint Messenger unauthenticated SQL injectionNuPoint Messenger in Mitel MiCollab through 9.8.0.33 fails to sanitize user input, allowing SQL injection. An unauthenticated attacker can reach the …EPSS 66%analysed9.8CVE-2024-35314Mitel micollab code injection vulnerabilityA vulnerability in the Desktop Client of Mitel MiCollab through 9.7.1.110, and MiVoice Business Solution Virtual Instance (MiVB SVI) 1.0.0.25, could …EPSS 1.8%9.8CVE-2022-41326Mitel micollab missing authorization vulnerabilityThe web conferencing component of Mitel MiCollab through 9.6.0.13 could allow an unauthenticated attacker to upload arbitrary scripts due to improper…EPSS 1.5%9.8CVE-2022-36452Mitel micollab unrestricted file upload vulnerabilityA vulnerability in the web conferencing component of Mitel MiCollab through 9.5.0.101 could allow an unauthenticated attacker to upload malicious fil…EPSS 0.90%

Source: NIST National Vulnerability Database (record CVE-2022-26143), CISA KEV, FIRST EPSS (scores of 2026-09-24). This page is refreshed as NVD updates the record.