| Title | Mitel MiCollab - Information Disclosure & Denial of Service |
|---|---|
| Author | theamanrawat |
| Severity | Critical |
| Impact | Attackers can retrieve sensitive information and cause performance degradation or denial of service, including DDoS attacks. |
| Remediation | Update to version 9.4 SP1 FP1 or later for MiCollab, and latest version for MiVoice Business Express. |
| CVSS Score | 9.8 |
| EPSS Score | 0.89199 |
| CVE ID | CVE-2022-26143 |
| CWE ID | CWE-306 |
| Shodan Query | html:"MiCollab End User Portal" |
| Tags | cve cve2022 mitel micollab kev passive vkev |
Mitel MiCollab before 9.4 SP1 FP1 and MiVoice Business Express through 8.1 contain a vulnerability in the TP-240 component caused by improper handling, letting remote attackers obtain sensitive information and cause denial of service, exploit requires remote access.
GET /ucs/micollab/version.json HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 11_6_6; de) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.4.2 Safari/605.1.15
Connection: close
Accept-Encoding: gzip
🔗 Nuclei Template: https://github.com/packetinside/nuclei-templates/blob/main/http/cves/2022/CVE-2022-26143.yaml
🦈 Packet Capture: ⬇️ Download cve-2022-26143.pcap
N/AN/A