An argument injection vulnerability has been identified in the administrative web interface of the Atos Unify OpenScape products "Session Border Controller" (SBC) and "Branch", before version V10 R3.4.0, and OpenScape "BCF" before versions V10R10.12.00 and V10R11.05.02. This allows an unauthenticated attacker to gain root access to the appliance via SSH (scope change) and also bypass authentication for the administrative interface and gain access as an arbitrary (administrative) user.
The vulnerability (CWE-88) involves improper neutralization of arguments in command invocations in the web administrative interface. An unauthenticated attacker can inject malicious arguments that are then passed to system processes without proper validation. As a result, it is possible to both bypass the administrative interface authentication mechanisms and escalate privileges to root level with SSH access (scope change according to CVSS vector).
An attacker gains full root access to the device via SSH and can also log into the administrative interface as any user (including administrator), meaning complete compromise of system confidentiality, integrity, and availability.
OpenScape SBC and Branch must be updated to version V10 R3.4.0 or later, and OpenScape BCF to version V10R10.12.00 or V10R11.05.02 (or later). Details are available in the manufacturer's official security advisory: OBSO-2310-01 at https://networks.unify.com/security/advisories/OBSO-2310-01.pdf. Until the patch is deployed, network access to the administrative interface should be restricted to trusted IP addresses only.
Atos Unify OpenScape Session Border Controller (SBC) and Branch before version V10 R3.4.0; Atos Unify OpenScape BCF before versions V10R10.12.00 and V10R11.05.02
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:HAtos Unify Openscape Bcf
APPAtos10 – 10r10.12.00 (excl.)Atos Unify Openscape Branch
APPAtos10 – 10r3.4.0 (excl.)Atos Unify Openscape Session Border Controller
APPAtos10 – 10r3.4.0 (excl.)
Related vulnerabilities
Atos Unify OpenScape SBC 10 before 10R3.1.3, OpenScape Branch 10 before 10R3.1.2, and OpenScape BCF 10 before ...
An issue was discovered in Atos Unify OpenScape SBC 9 and 10 before 10R2.2.1, Atos Unify OpenScape Branch 9 an...
RCE dla nieuwierzytelnionych użytkowników w Atos Unify OpenScape 4000
RCE bez uwierzytelnienia w Atos Unify OpenScape 4000 Platform
RCE bez uwierzytelnienia w Atos Unify OpenScape 4000 – command injection