Mitel MiCollab <= 9.4 SP1 Information Disclosure and DoS (22-0001)

critical Nessus Plugin ID 200313


An application running on the remote web server is affected by an information disclosure and denial of service vulnerability.


According to its version number, the Mitel MiCollab software is 9.4 SP1 (9.4.107) or prior. It is, therefore, affected by the following vulnerability:

- A vulnerability has been identified in MiCollab and MiVoice Business Express that may allow a malicious actor to gain unauthorized access to sensitive information and services, cause performance degradations or a denial of service condition on the affected system. If exploited with a denial of service attack, the impacted system may cause significant outbound traffic impacting availability of other services. This was exploited in the wild in February and March 2022 for the TP240PhoneHome DDoS attack. (CVE-2022-26143)

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.


Upgrade to Mitel MiCollab version 9.4 SP1 FP1 (9.4.109) or later.

See Also

Plugin Details

Severity: Critical

ID: 200313

File Name: mitel_micollab_CVE-2022-26143.nasl

Version: 1.3

Type: remote

Family: CGI abuses

Published: 6/11/2024

Updated: 6/12/2024

Supported Sensors: Nessus

Risk Information


Risk Factor: High

Score: 7.4


Risk Factor: High

Base Score: 9

Temporal Score: 7.4

Vector: CVSS2#AV:N/AC:L/Au:N/C:P/I:P/A:C

CVSS Score Source: CVE-2022-26143


Risk Factor: Critical

Base Score: 9.8

Temporal Score: 9.1

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Temporal Vector: CVSS:3.0/E:F/RL:O/RC:C

Vulnerability Information

CPE: cpe:/a:mitel:micollab

Required KB Items: installed_sw/Mitel MiCollab

Exploit Available: true

Exploit Ease: Exploits are available

Patch Publication Date: 3/9/2022

Vulnerability Publication Date: 3/8/2022

CISA Known Exploited Vulnerability Due Dates: 4/15/2022

Reference Information

CVE: CVE-2022-26143