Skip to content
COOEY

EXPOSURES › CVE-2022-26143

CVE-2022-26143

HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2022-03-25 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2022-26143 ↗
⌖ EXPLOITED IN THE WILD SHAME 65/100 exploited-in-wildunpatched

Mitel's MiCollab and MiVoice Business Express suffered an access control vulnerability allowing unauthorized access, DoS, and data exposure.

The access control flaw in Mitel's MiCollab and MiVoice Business Express allowed attackers to bypass security controls, leading to unauthorized data access and denial-of-service conditions. DIB organizations must ensure their Mitel deployments are patched and monitored, as this vulnerability was actively exploited in the wild. Failure to patch such access control flaws can result in significant data breaches and compliance violations under NIST 800-171.

Shame score — The vulnerability was actively exploited in the wild (KEV), indicating negligent patching and avoidable exposure of sensitive information.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

A vulnerability has been identified in MiCollab and MiVoice Business Express that may allow a malicious actor to gain unauthorized access to sensitive information and services, cause performance degradations or a denial of service condition on the affected system.

AFFECTED FEDRAMP PRODUCTS · 0
No correlated FedRAMP products.