VYPR
Vendor

Atos Unify

Products
10
CVEs
15
Across products
17
Status
Private

Products

10

Recent CVEs

15
  • CVE-2023-6269CriDec 5, 2023
    risk 0.65cvss 10.0epss 0.02

    An argument injection vulnerability has been identified in the administrative web interface of the Atos Unify OpenScape products "Session Border Controller" (SBC) and "Branch", before version V10 R3.4.0, and OpenScape "BCF" before versions V10R10.12.00 and V10R11.05.02. This…

  • CVE-2023-36619CriOct 4, 2023
    risk 0.64cvss 9.8epss 0.04

    Atos Unify OpenScape Session Border Controller through V10 R3.01.03 allows execution of administrative scripts by unauthenticated users.

  • CVE-2023-40265HigFeb 8, 2024
    risk 0.57cvss 8.8epss 0.01

    An issue was discovered in Atos Unify OpenScape Xpressions WebAssistant V7 before V7R1 FR5 HF42 P911. It allows authenticated remote code execution via file upload.

  • CVE-2023-45355HigOct 9, 2023
    risk 0.57cvss 8.8epss 0.01

    Atos Unify OpenScape 4000 Platform V10 R1 before Hotfix V10 R1.42.2 and 4000 and Manager Platform V10 R1 before Hotfix V10 R1.42.2 allow command injection by an authenticated attacker into the platform operating system, leading to administrative access via the webservice. This…

  • CVE-2023-45354HigOct 9, 2023
    risk 0.57cvss 8.8epss 0.01

    Atos Unify OpenScape Common Management Portal V10 before V10 R4.17.0 and V10 R5.1.0 allows an authenticated remote attacker to execute arbitrary code on the operating system by using the Common Management Portal web interface. This is also known as OCMP-6589.

  • CVE-2023-45353HigOct 9, 2023
    risk 0.57cvss 8.8epss 0.01

    Atos Unify OpenScape Common Management Portal V10 before V10 R4.17.0 and V10 R5.1.0 allows an authenticated attacker to execute arbitrary code on the operating system by leveraging the Common Management Portal web interface for Authenticated remote upload and creation of…

  • CVE-2023-45352HigOct 9, 2023
    risk 0.57cvss 8.8epss 0.01

    Atos Unify OpenScape Common Management Portal V10 before V10 R4.17.0 and V10 R5.1.0 allows an authenticated attacker to execute arbitrary code on the operating system via a Common Management Portal web interface Path traversal vulnerability allowing write access outside the…

  • CVE-2023-45350HigOct 9, 2023
    risk 0.57cvss 8.8epss 0.01

    Atos Unify OpenScape 4000 Manager V10 R1 before V10 R1.42.1 and 4000 Manager V10 R0 allow Privilege escalation that may lead to the ability of an authenticated attacker to run arbitrary code via AScm. This is also known as OSFOURK-24034.

  • CVE-2023-36618HigOct 4, 2023
    risk 0.57cvss 8.8epss 0.03

    Atos Unify OpenScape Session Border Controller through V10 R3.01.03 allows execution of OS commands as root user by low-privileged authenticated users.

  • CVE-2022-36444HigJul 25, 2022
    risk 0.56cvss 8.6epss 0.01

    An issue was discovered in Atos Unify OpenScape SBC 9 and 10 before 10R2.2.1, Atos Unify OpenScape Branch 9 and 10 before version 10R2.1.1, and Atos Unify OpenScape BCF 10 before 10R9.12.1. A remote code execution vulnerability may allow an unauthenticated attacker (with network…

  • CVE-2023-48166HigJan 12, 2024
    risk 0.49cvss 7.5epss 0.01

    A directory traversal vulnerability in the SOAP Server integrated in Atos Unify OpenScape Voice V10 before V10R3.26.1 allows a remote attacker to view the contents of arbitrary files in the local file system. An unauthenticated attacker might obtain sensitive files that allow…

  • CVE-2019-19866HigFeb 21, 2020
    risk 0.49cvss 7.5epss 0.02

    Atos Unify OpenScape UC Web Client V9 before version V9 R4.31.0 and V10 before version V10 R0.6.0 allows remote attackers to obtain sensitive information. By iterating the value of conferenceId to getMailFunction in the JSON API, one can enumerate all conferences scheduled on…

  • CVE-2019-19865MedFeb 21, 2020
    risk 0.40cvss 6.1epss 0.01

    Atos Unify OpenScape UC Application V9 before version V9 R4.31.0 and V10 before version V10 R0.6.0 allows XSS. An attacker could exploit this by convincing an authenticated user to inject arbitrary JavaScript code in the Profile Name field. A browser would execute this stored…

  • CVE-2013-4781Jul 18, 2013
    risk 0.00cvss epss 0.03

    core/getLog.php on the Siemens Enterprise OpenScape Branch appliance and OpenScape Session Border Controller (SBC) before 2 R0.32.0, and 7 before 7 R1.7.0, allows remote attackers to execute arbitrary commands via unspecified vectors.

  • CVE-2013-4778Jul 18, 2013
    risk 0.00cvss epss 0.01

    core/getLog.php on the Siemens Enterprise OpenScape Branch appliance and OpenScape Session Border Controller (SBC) before 2 R0.32.0, and 7 before 7 R1.7.0, allows remote attackers to obtain sensitive server and statistics information via unspecified vectors.