The TP-240 (aka tp240dvr) component in Mitel MiCollab before 9.4 SP1 FP1 and MiVoice Business Express through 8.1 allows remote attackers to obtain sensitive information and cause a denial of service (performance degradation and excessive outbound traffic). This was exploited in the wild in February and March 2022 for the TP240PhoneHome DDoS attack.
2022-03-10T17:47:32.813
2025-03-14T20:00:05.833
Analyzed
CVSSv3.1: 9.8 (CRITICAL)
AV:N/AC:L/Au:N/C:P/I:P/A:C
10.0
8.5
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | mitel | micollab | < 9.4 | Yes |
Application | mitel | micollab | 9.4 | Yes |
Application | mitel | micollab | 9.4 | Yes |
Application | mitel | mivoice_business_express | ≤ 8.1 | Yes |