Show filters
40 Total Results
Displaying 1-10 of 40
Sort by:
Attacker Value
Unknown
CVE-2023-40264
Disclosure Date: February 08, 2024 (last updated February 17, 2024)
An issue was discovered in Atos Unify OpenScape Voice Trace Manager V8 before V8 R0.9.11. It allows authenticated path traversal in the user interface.
0
Attacker Value
Unknown
CVE-2023-40263
Disclosure Date: February 08, 2024 (last updated February 15, 2024)
An issue was discovered in Atos Unify OpenScape Voice Trace Manager V8 before V8 R0.9.11. It allows authenticated command injection via ftp.
0
Attacker Value
Unknown
CVE-2023-40262
Disclosure Date: February 08, 2024 (last updated February 15, 2024)
An issue was discovered in Atos Unify OpenScape Voice Trace Manager V8 before V8 R0.9.11. It allows unauthenticated Stored Cross-Site Scripting (XSS) in the administration component via Access Request.
0
Attacker Value
Unknown
CVE-2023-40266
Disclosure Date: February 08, 2024 (last updated February 16, 2024)
An issue was discovered in Atos Unify OpenScape Xpressions WebAssistant V7 before V7R1 FR5 HF42 P911. It allows path traversal.
0
Attacker Value
Unknown
CVE-2023-40265
Disclosure Date: February 08, 2024 (last updated February 16, 2024)
An issue was discovered in Atos Unify OpenScape Xpressions WebAssistant V7 before V7R1 FR5 HF42 P911. It allows authenticated remote code execution via file upload.
0
Attacker Value
Unknown
CVE-2023-48166
Disclosure Date: January 12, 2024 (last updated January 23, 2024)
A directory traversal vulnerability in the SOAP Server integrated in Atos Unify OpenScape Voice V10 before V10R3.26.1 allows a remote attacker to view the contents of arbitrary files in the local file system. An unauthenticated attacker might obtain sensitive files that allow for the compromise of the underlying system.
0
Attacker Value
Unknown
CVE-2023-6269
Disclosure Date: December 05, 2023 (last updated December 12, 2023)
An argument injection vulnerability has been identified in the
administrative web interface of the Atos Unify OpenScape products "Session Border Controller" (SBC) and "Branch", before version V10 R3.4.0, and OpenScape "BCF" before versions V10R10.12.00 and V10R11.05.02. This allows an
unauthenticated attacker to gain root access to the appliance via SSH (scope change) and also bypass authentication for the administrative interface and gain
access as an arbitrary (administrative) user.
0
Attacker Value
Unknown
CVE-2023-45356
Disclosure Date: October 09, 2023 (last updated October 13, 2023)
Atos Unify OpenScape 4000 Platform V10 R1 before Hotfix V10 R1.42.2 4000 and Manager Platform V10 R1 before Hotfix V10 R1.42.2 allow command injection by an authenticated attacker into the platform operating system, leading to administrative access, via dtb pages of the platform portal. This is also known as OSFOURK-23719.
0
Attacker Value
Unknown
CVE-2023-45355
Disclosure Date: October 09, 2023 (last updated October 13, 2023)
Atos Unify OpenScape 4000 Platform V10 R1 before Hotfix V10 R1.42.2 and 4000 and Manager Platform V10 R1 before Hotfix V10 R1.42.2 allow command injection by an authenticated attacker into the platform operating system, leading to administrative access via the webservice. This is also known as OSFOURK-24120.
0
Attacker Value
Unknown
CVE-2023-45354
Disclosure Date: October 09, 2023 (last updated October 13, 2023)
Atos Unify OpenScape Common Management Portal V10 before V10 R4.17.0 and V10 R5.1.0 allows an authenticated remote attacker to execute arbitrary code on the operating system by using the Common Management Portal web interface. This is also known as OCMP-6589.
0