Leaving ports open to all is a no no, this can causes all sorts of weird issues. We always get ports locked down to our source IP or look at a secure VPN connection.
Its just not worth the risk, also I have read other systems (not Mitel) having similar issues with ports open. I remember reading Avaya suggested turning off auto phone registration as I believe people were hacking system and auto registering new devices to make calls. What ends up being a really handy install tool for an engineer ends up being a great tool for hackers.