Mitel MiVoice <= 8.1 SP1 Information Disclosure and DoS (22-0001)

critical Nessus Plugin ID 200312

Synopsis

An application running on the remote web server is affected by an information disclosure and denial of service vulnerability.

Description

According to its version number, the Mitel MiVoice software is R8.1 or prior. It is, therefore, affected by the following vulnerability:

- A vulnerability has been identified in MiCollab and MiVoice Business Express that may allow a malicious actor to gain unauthorized access to sensitive information and services, cause performance degradations or a denial of service condition on the affected system. If exploited with a denial of service attack, the impacted system may cause significant outbound traffic impacting availability of other services. This was exploited in the wild in February and March 2022 for the TP240PhoneHome DDoS attack. (CVE-2022-26143)

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.

Solution

Upgrade to Mitel MiVoice version 8.2 or later.

See Also

https://blog.cloudflare.com/cve-2022-26143

http://www.nessus.org/u?f392cc29

Plugin Details

Severity: Critical

ID: 200312

File Name: mitel_mivoice_CVE-2022-26143.nasl

Version: 1.3

Type: local

Family: CGI abuses

Published: 6/11/2024

Updated: 6/12/2024

Supported Sensors: Nessus

Risk Information

VPR

Risk Factor: High

Score: 7.4

CVSS v2

Risk Factor: High

Base Score: 9

Temporal Score: 7.4

Vector: CVSS2#AV:N/AC:L/Au:N/C:P/I:P/A:C

CVSS Score Source: CVE-2022-26143

CVSS v3

Risk Factor: Critical

Base Score: 9.8

Temporal Score: 9.1

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Temporal Vector: CVSS:3.0/E:F/RL:O/RC:C

Vulnerability Information

CPE: cpe:/a:mitel:mivoice_connect

Required KB Items: installed_sw/Mitel MiVoice Connect Server

Exploit Available: true

Exploit Ease: Exploits are available

Patch Publication Date: 3/9/2022

Vulnerability Publication Date: 3/8/2022

CISA Known Exploited Vulnerability Due Dates: 4/15/2022

Reference Information

CVE: CVE-2022-26143