CVE-2023-29473: Command Injection
webservice in Atos Unify OpenScape 4000 Platform and OpenScape 4000 Manager Platform 10 R1 before 10 R1.34.4 allows an unauthenticated attacker to run arbitrary commands on the platform operating system and achieve administrative access, aka OSFOURK-23710.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for this issue?
The vulnerability ID is CVE-2023-29473.
What is the severity rating of CVE-2023-29473?
The severity rating of CVE-2023-29473 is critical.
Which software is affected by CVE-2023-29473?
CVE-2023-29473 affects Atos Unify OpenScape 4000 Platform and OpenScape 4000 Manager Platform 10 R1 before 10 R1.34.4.
How can an attacker exploit CVE-2023-29473?
An unauthenticated attacker can exploit CVE-2023-29473 by running arbitrary commands on the platform operating system and achieving administrative access.
Are there any references available for CVE-2023-29473?
Yes, references for CVE-2023-29473 can be found at the following links: [Reference 1](https://networks.unify.com/security/advisories/OBSO-2303-01.pdf) and [Reference 2](https://www.news.de/technik/856806612/unify-openscape-4000-gefaehrdet-it-sicherheitswarnung-vom-bsi-und-bug-report-betroffene-systeme-und-produkte-neue-versionen-und-updates/1/).