PT-2023-7028 · Atos · Atos Unify Openscape Session Border Controller+2

Armin Weihbold

·

Published

2023-07-06

·

Updated

2023-10-07

·

CVE-2023-36619

CVSS v2.0

10

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Atos Unify OpenScape Session Border Controller versions through V10 R3.01.03 Atos Unify OpenScape Branch (affected versions not specified) Atos Unify OpenScape BCF (affected versions not specified)
Description The issue allows execution of administrative scripts by unauthenticated users due to insufficient input validation in the implementation of the application programming interface of the Session Border Controller's firmware. This can be exploited remotely using HTTP requests, potentially allowing an attacker to perform arbitrary actions.
Recommendations For Atos Unify OpenScape Session Border Controller versions through V10 R3.01.03: Update to a version that addresses the insufficient input validation issue. For Atos Unify OpenScape Branch: At the moment, there is no information about a newer version that contains a fix for this vulnerability. For Atos Unify OpenScape BCF: At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

RCE

Weakness Enumeration

Related Identifiers

BDU:2023-08050
CVE-2023-36619

Affected Products

Atos Unify Openscape Bcf
Atos Unify Openscape Branch
Atos Unify Openscape Session Border Controller