CVE-2023-6269
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
05/12/2023
Last modified:
13/12/2023
Description
An argument injection vulnerability has been identified in the <br />
administrative web interface of the Atos Unify OpenScape products "Session Border Controller" (SBC) and "Branch", before version V10 R3.4.0, and OpenScape "BCF" before versions V10R10.12.00 and V10R11.05.02. This allows an <br />
unauthenticated attacker to gain root access to the appliance via SSH (scope change) and also bypass authentication for the administrative interface and gain<br />
access as an arbitrary (administrative) user.
Impact
Base Score 3.x
9.80
Severity 3.x
CRITICAL
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:atos:unify_openscape_bcf:*:*:*:*:*:*:*:* | 10 (including) | 10r10.12.00 (excluding) |
| cpe:2.3:a:atos:unify_openscape_branch:*:*:*:*:*:*:*:* | 10 (including) | 10r3.4.0 (excluding) |
| cpe:2.3:a:atos:unify_openscape_session_border_controller:*:*:*:*:*:*:*:* | 10 (including) | 10r3.4.0 (excluding) |
To consult the complete list of CPE names with products and versions, see this page



