First published: Thu Apr 12 2018(Updated: )
The web-based management (WBM) interface in Unify (former Siemens) OpenStage SIP and OpenScape Desk Phone IP V3 devices before R3.32.0 generates session cookies with insufficient entropy, which makes it easier for remote attackers to hijack sessions via a brute-force attack.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Unify Openstage Sip | <r3.32.0 | |
Unify Openstage 20 | ||
Unify Openstage 40 | ||
Unify Openstage 60 | ||
Unify Openscape Desk Phone Ip Sip | <r3.32.0 | |
Atos Openscape Desk Phone Ip 35g | ||
Atos Openscape Desk Phone Ip 35g Eco | ||
Atos Openscape Desk Phone Ip 55g |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2014-8422 is a vulnerability that affects the web-based management (WBM) interface in Unify OpenStage SIP and OpenScape Desk Phone IP V3 devices before R3.32.0.
CVE-2014-8422 allows remote attackers to hijack sessions via a brute-force attack on the session cookies.
CVE-2014-8422 has a severity score of 8.1 (high).
Unify OpenStage SIP and OpenScape Desk Phone IP V3 devices before R3.32.0 are affected by CVE-2014-8422.
To mitigate CVE-2014-8422, users should update the affected devices to version R3.32.0 or later.