CVE-2023-48166
Description
A directory traversal vulnerability in the SOAP Server integrated in Atos Unify OpenScape Voice V10 before V10R3.26.1 allows a remote attacker to view the contents of arbitrary files in the local file system. An unauthenticated attacker might obtain sensitive files that allow for the compromise of the underlying system.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
A path traversal vulnerability in the SOAP Server of Atos Unify OpenScape Voice V10 allows unauthenticated remote attackers to read arbitrary files.
Vulnerability
The SOAP Server integrated in Atos Unify OpenScape Voice V10 before version V10R3.26.1 is vulnerable to a directory traversal attack. An unauthenticated remote attacker can exploit this to read arbitrary files from the local file system. [1]
Exploitation
The attacker does not require authentication or user interaction. The vulnerability is reachable over the network (adjacent network, CVSS AV:A) via the SOAP interface. By crafting a malicious request with path traversal sequences (e.g., ../), the attacker can navigate outside the intended directory and retrieve sensitive files. [1]
Impact
Successful exploitation allows the attacker to read arbitrary files, potentially including configuration files, credentials, or other sensitive data. This could lead to full compromise of the underlying system. The CVSSv3 base score is 7.4 (High) with confidentiality impact High, integrity and availability None. [1]
Mitigation
The vendor released a fix in version V10R3.26.1. Users should update to this version or later. No workarounds are mentioned. The vulnerability was reported on 2 Nov 2023 and fixed on 19 Dec 2023. [1]
AI Insight generated on May 25, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
2- Atos Unify/OpenScape Voicedescription
- Range: V10 before V10R3.26.1
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
2News mentions
0No linked articles in our index yet.