Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-xh7f-2c8g-37p4

Опубликовано: 11 мар. 2022
Источник: github
Github: Не прошло ревью
CVSS3: 9.8

Описание

The TP-240 (aka tp240dvr) component in Mitel MiCollab before 9.4 SP1 FP1 and MiVoice Business Express through 8.1 allows remote attackers to obtain sensitive information and cause a denial of service (performance degradation and excessive outbound traffic). This was exploited in the wild in February and March 2022 for the TP240PhoneHome DDoS attack.

The TP-240 (aka tp240dvr) component in Mitel MiCollab before 9.4 SP1 FP1 and MiVoice Business Express through 8.1 allows remote attackers to obtain sensitive information and cause a denial of service (performance degradation and excessive outbound traffic). This was exploited in the wild in February and March 2022 for the TP240PhoneHome DDoS attack.

EPSS

Процентиль: 100%
0.89199
Высокий

9.8 Critical

CVSS3

Дефекты

CWE-306
CWE-863

Связанные уязвимости

CVSS3: 9.8
nvd
почти 4 года назад

The TP-240 (aka tp240dvr) component in Mitel MiCollab before 9.4 SP1 FP1 and MiVoice Business Express through 8.1 allows remote attackers to obtain sensitive information and cause a denial of service (performance degradation and excessive outbound traffic). This was exploited in the wild in February and March 2022 for the TP240PhoneHome DDoS attack.

CVSS3: 9.4
fstec
почти 4 года назад

Уязвимость микропрограммного обеспечения интерфейсных плат TP-240 платформ для совместной работы MiCollab и MiVoice Business Express, связанная с ошибками при обработке XML-сообщений, позволяющая нарушителю читать и изменять конфигурацию уязвимого устройства или вызвать отказ в обслуживании

EPSS

Процентиль: 100%
0.89199
Высокий

9.8 Critical

CVSS3

Дефекты

CWE-306
CWE-863