VYPR
Critical severity9.8CISA KEVNVD Advisory· Published Mar 10, 2022· Updated Jun 17, 2026

CVE-2022-26143

CVE-2022-26143

Description

The TP-240 (aka tp240dvr) component in Mitel MiCollab before 9.4 SP1 FP1 and MiVoice Business Express through 8.1 allows remote attackers to obtain sensitive information and cause a denial of service (performance degradation and excessive outbound traffic). This was exploited in the wild in February and March 2022 for the TP240PhoneHome DDoS attack.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

8
  • Mitel/Micollab5 versions
    cpe:2.3:a:mitel:micollab:*:*:*:*:*:-:*:*+ 4 more
    • cpe:2.3:a:mitel:micollab:*:*:*:*:*:-:*:*range: <9.4
    • cpe:2.3:a:mitel:micollab:9.4:-:*:*:*:-:*:*
    • cpe:2.3:a:mitel:micollab:9.4:sp1:*:*:*:-:*:*
    • (no CPE)
    • (no CPE)range: <9.4 SP1 FP1
  • cpe:2.3:a:mitel:mivoice_business_express:*:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:mitel:mivoice_business_express:*:*:*:*:*:*:*:*range: <=8.1
    • (no CPE)range: <=8.1
  • Mitel/TP-240llm-create
    Range: <9.4 SP1 FP1 for MiCollab, <=8.1 for MiVoice Business Express

Patches

Vulnerability mechanics

References

8

News mentions

0

No linked articles in our index yet.