PT-2023-7028 · Atos · Atos Unify Openscape Session Border Controller+2

Armin Weihbold

·

Publicado

2023-07-06

·

Atualizado

2023-10-07

·

CVE-2023-36619

CVSS v2.0

10

Crítica

VetorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Atos Unify OpenScape Session Border Controller versions through V10 R3.01.03 Atos Unify OpenScape Branch (affected versions not specified) Atos Unify OpenScape BCF (affected versions not specified)
Description The issue allows execution of administrative scripts by unauthenticated users due to insufficient input validation in the implementation of the application programming interface of the Session Border Controller's firmware. This can be exploited remotely using HTTP requests, potentially allowing an attacker to perform arbitrary actions.
Recommendations For Atos Unify OpenScape Session Border Controller versions through V10 R3.01.03: Update to a version that addresses the insufficient input validation issue. For Atos Unify OpenScape Branch: At the moment, there is no information about a newer version that contains a fix for this vulnerability. For Atos Unify OpenScape BCF: At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

RCE

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2023-08050
CVE-2023-36619

Produtos afetados

Atos Unify Openscape Bcf
Atos Unify Openscape Branch
Atos Unify Openscape Session Border Controller