PT-2022-27856 · Atos · Atos Unify Openscape 4000 Assistant+1
Published
2022-12-13
·
Updated
2022-12-27
·
CVE-2022-46404
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Atos Unify OpenScape 4000 Assistant versions 8 before R2.22.18
Atos Unify OpenScape 4000 Assistant versions 10 before 0.28.13
Atos Unify OpenScape 4000 Assistant versions 10 R1 before R1.34.4
Atos Unify OpenScape 4000 Manager versions 8 before R2.22.18
Atos Unify OpenScape 4000 Manager versions 10 before 0.28.13
Atos Unify OpenScape 4000 Manager versions 10 R1 before R1.34.4
Description
A command injection issue has been identified that may allow an unauthenticated attacker to upload arbitrary files and achieve administrative access to the system.
Recommendations
For Atos Unify OpenScape 4000 Assistant version 8, update to R2.22.18 or later.
For Atos Unify OpenScape 4000 Assistant version 10, update to 0.28.13 or later.
For Atos Unify OpenScape 4000 Assistant version 10 R1, update to R1.34.4 or later.
For Atos Unify OpenScape 4000 Manager version 8, update to R2.22.18 or later.
For Atos Unify OpenScape 4000 Manager version 10, update to 0.28.13 or later.
For Atos Unify OpenScape 4000 Manager version 10 R1, update to R1.34.4 or later.
Fix
Command Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Atos Unify Openscape 4000 Assistant
Atos Unify Openscape 4000 Manager