CVE-2014-8422: High severity unify openstage sip vulnerability
The web-based management (WBM) interface in Unify (former Siemens) OpenStage SIP and OpenScape Desk Phone IP V3 devices before R3.32.0 generates session cookies with insufficient entropy, which makes it easier for remote attackers to hijack sessions via a brute-force attack.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2014-8422?
CVE-2014-8422 is a vulnerability that affects the web-based management (WBM) interface in Unify OpenStage SIP and OpenScape Desk Phone IP V3 devices before R3.32.0.
How does CVE-2014-8422 impact the affected software?
CVE-2014-8422 allows remote attackers to hijack sessions via a brute-force attack on the session cookies.
What is the severity of CVE-2014-8422?
CVE-2014-8422 has a severity score of 8.1 (high).
Which software versions are affected by CVE-2014-8422?
Unify OpenStage SIP and OpenScape Desk Phone IP V3 devices before R3.32.0 are affected by CVE-2014-8422.
How can CVE-2014-8422 be mitigated?
To mitigate CVE-2014-8422, users should update the affected devices to version R3.32.0 or later.