CVE-2023-6269

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
05/12/2023
Last modified:
13/12/2023

Description

An argument injection vulnerability has been identified in the <br /> administrative web interface of the Atos Unify OpenScape products "Session Border Controller" (SBC) and "Branch", before version V10 R3.4.0, and OpenScape "BCF" before versions V10R10.12.00 and V10R11.05.02. This allows an <br /> unauthenticated attacker to gain root access to the appliance via SSH (scope change) and also bypass authentication for the administrative interface and gain<br /> access as an arbitrary (administrative) user.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:atos:unify_openscape_bcf:*:*:*:*:*:*:*:* 10 (including) 10r10.12.00 (excluding)
cpe:2.3:a:atos:unify_openscape_branch:*:*:*:*:*:*:*:* 10 (including) 10r3.4.0 (excluding)
cpe:2.3:a:atos:unify_openscape_session_border_controller:*:*:*:*:*:*:*:* 10 (including) 10r3.4.0 (excluding)