HIGH🇵🇱 Wersja polska

CVE-2022-36444

CVSS 8.6v3.1pub. 2022-07-25upd. 2024-11-21

An issue was discovered in Atos Unify OpenScape SBC 9 and 10 before 10R2.2.1, Atos Unify OpenScape Branch 9 and 10 before version 10R2.1.1, and Atos Unify OpenScape BCF 10 before 10R9.12.1. A remote code execution vulnerability may allow an unauthenticated attacker (with network access to the admin interface) to disrupt system availability or potentially compromise the confidentiality and integrity of the system.

CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H
  • Atos Unify Openscape Bcf

    APP
    Atos
    10 – 10r9.12.1 (excl.)
  • Atos Unify Openscape Branch

    APP
    Atos
    910 – 10r2.1.1 (excl.)
  • Atos Unify Openscape Session Border Controller

    APP
    Atos
    910 – 10r2.2.1 (excl.)
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
RCEAuth Bypass
CWE
References

Related vulnerabilities

CVE-2023-6269CRITICAL10.0PL ✓same product

Atos Unify OpenScape — argument injection umożliwiający przejęcie roota przez SSH

CVE-2023-30638HIGH7.2same product

Atos Unify OpenScape SBC 10 before 10R3.1.3, OpenScape Branch 10 before 10R3.1.2, and OpenScape BCF 10 before ...

CVE-2023-35034CRITICAL9.8PL ✓same vendor

RCE dla nieuwierzytelnionych użytkowników w Atos Unify OpenScape 4000

CVE-2023-29473CRITICAL9.8PL ✓same vendor

RCE bez uwierzytelnienia w Atos Unify OpenScape 4000 Platform

CVE-2023-29474CRITICAL9.8PL ✓same vendor

RCE bez uwierzytelnienia w Atos Unify OpenScape 4000 – command injection