The TP-240 (aka tp240dvr) component in Mitel MiCollab before 9.4 SP1 FP1 and MiVoice Business Express through 8.1 allows remote attackers to obtain sensitive information and cause a denial of service (performance degradation and excessive outbound traffic). This was exploited in the wild in February and March 2022 for the TP240PhoneHome DDoS attack.
2022-03-10T17:47:32.813
2025-11-03T15:15:14.620
Analyzed
CVSSv3.1: 9.8 (CRITICAL)
AV:N/AC:L/Au:N/C:P/I:P/A:C
10.0
8.5
| Type | Vendor | Product | Version/Range | Vulnerable? |
|---|---|---|---|---|
| Application | mitel | micollab | < 9.4 | Yes |
| Application | mitel | micollab | 9.4 | Yes |
| Application | mitel | micollab | 9.4 | Yes |
| Application | mitel | mivoice_business_express | ≤ 8.1 | Yes |