PT-2023-7028 · Atos · Atos Unify Openscape Session Border Controller+2
Armin Weihbold
·
Published
2023-07-06
·
Updated
2023-10-07
·
CVE-2023-36619
CVSS v2.0
10
Critical
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Atos Unify OpenScape Session Border Controller versions through V10 R3.01.03
Atos Unify OpenScape Branch (affected versions not specified)
Atos Unify OpenScape BCF (affected versions not specified)
Description
The issue allows execution of administrative scripts by unauthenticated users due to insufficient input validation in the implementation of the application programming interface of the Session Border Controller's firmware. This can be exploited remotely using HTTP requests, potentially allowing an attacker to perform arbitrary actions.
Recommendations
For Atos Unify OpenScape Session Border Controller versions through V10 R3.01.03: Update to a version that addresses the insufficient input validation issue.
For Atos Unify OpenScape Branch: At the moment, there is no information about a newer version that contains a fix for this vulnerability.
For Atos Unify OpenScape BCF: At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Atos Unify Openscape Bcf
Atos Unify Openscape Branch
Atos Unify Openscape Session Border Controller