CISA Known Exploited Vulnerability

CVE-2022-26143

Mitel · MiCollab, MiVoice Business Express

MiCollab, MiVoice Business Express Access Control Vulnerability

Date added
BOD 22-01 due date
CWE CWE-306, CWE-406
Ransomware Unknown

CISA description

A vulnerability has been identified in MiCollab and MiVoice Business Express that may allow a malicious actor to gain unauthorized access to sensitive information and services, cause performance degradations or a denial of service condition on the affected system.

Required action

Apply updates per vendor instructions.