CVE-2014-2650: Command Injection
Unify OpenStage / OpenScape Desk Phone IP before V3 R3.11.0 SIP has an OS command injection vulnerability in the web based management interface
Affected Software
Event History
Frequently Asked Questions
What is CVE-2014-2650?
CVE-2014-2650 is a vulnerability in the Unify OpenStage / OpenScape Desk Phone IP before V3 R3.11.0 SIP that allows for OS command injection through the web-based management interface.
Is Atos Openstage 80 Firmware affected by CVE-2014-2650?
Yes, Atos Openstage 80 Firmware v3-r3.11.0 is affected by CVE-2014-2650.
How severe is CVE-2014-2650?
CVE-2014-2650 has a severity rating of 9.8, which is considered critical.
How can I fix CVE-2014-2650?
To fix CVE-2014-2650, update your Unify OpenStage / OpenScape Desk Phone IP to V3 R3.11.0 or later.
Where can I find more information about CVE-2014-2650?
You can find more information about CVE-2014-2650 in the security advisories from Unify: [link to security advisories](https://networks.unify.com/security/advisories/OBSO-1403-01.pdf).