VYPR
Unrated severityNVD Advisory· Published Jan 12, 2024· Updated Jun 20, 2025

CVE-2023-48166

CVE-2023-48166

Description

A directory traversal vulnerability in the SOAP Server integrated in Atos Unify OpenScape Voice V10 before V10R3.26.1 allows a remote attacker to view the contents of arbitrary files in the local file system. An unauthenticated attacker might obtain sensitive files that allow for the compromise of the underlying system.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

A path traversal vulnerability in the SOAP Server of Atos Unify OpenScape Voice V10 allows unauthenticated remote attackers to read arbitrary files.

Vulnerability

The SOAP Server integrated in Atos Unify OpenScape Voice V10 before version V10R3.26.1 is vulnerable to a directory traversal attack. An unauthenticated remote attacker can exploit this to read arbitrary files from the local file system. [1]

Exploitation

The attacker does not require authentication or user interaction. The vulnerability is reachable over the network (adjacent network, CVSS AV:A) via the SOAP interface. By crafting a malicious request with path traversal sequences (e.g., ../), the attacker can navigate outside the intended directory and retrieve sensitive files. [1]

Impact

Successful exploitation allows the attacker to read arbitrary files, potentially including configuration files, credentials, or other sensitive data. This could lead to full compromise of the underlying system. The CVSSv3 base score is 7.4 (High) with confidentiality impact High, integrity and availability None. [1]

Mitigation

The vendor released a fix in version V10R3.26.1. Users should update to this version or later. No workarounds are mentioned. The vulnerability was reported on 2 Nov 2023 and fixed on 19 Dec 2023. [1]

AI Insight generated on May 25, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

2

News mentions

0

No linked articles in our index yet.