PT-2022-27856 · Atos · Atos Unify Openscape 4000 Assistant+1

Published

2022-12-13

·

Updated

2022-12-27

·

CVE-2022-46404

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Atos Unify OpenScape 4000 Assistant versions 8 before R2.22.18 Atos Unify OpenScape 4000 Assistant versions 10 before 0.28.13 Atos Unify OpenScape 4000 Assistant versions 10 R1 before R1.34.4 Atos Unify OpenScape 4000 Manager versions 8 before R2.22.18 Atos Unify OpenScape 4000 Manager versions 10 before 0.28.13 Atos Unify OpenScape 4000 Manager versions 10 R1 before R1.34.4
Description A command injection issue has been identified that may allow an unauthenticated attacker to upload arbitrary files and achieve administrative access to the system.
Recommendations For Atos Unify OpenScape 4000 Assistant version 8, update to R2.22.18 or later. For Atos Unify OpenScape 4000 Assistant version 10, update to 0.28.13 or later. For Atos Unify OpenScape 4000 Assistant version 10 R1, update to R1.34.4 or later. For Atos Unify OpenScape 4000 Manager version 8, update to R2.22.18 or later. For Atos Unify OpenScape 4000 Manager version 10, update to 0.28.13 or later. For Atos Unify OpenScape 4000 Manager version 10 R1, update to R1.34.4 or later.

Fix

Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2022-46404

Affected Products

Atos Unify Openscape 4000 Assistant
Atos Unify Openscape 4000 Manager