CVE-2023-29475: Command Injection
inventory in Atos Unify OpenScape 4000 Platform and OpenScape 4000 Manager Platform 10 R1 before 10 R1.34.4 allows an unauthenticated attacker to run arbitrary commands on the platform operating system and achieve administrative access, aka OSFOURK-23543.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID?
The vulnerability ID is CVE-2023-29475.
What is the severity of CVE-2023-29475?
The severity of CVE-2023-29475 is critical with a CVSS score of 9.8.
Which software is affected by CVE-2023-29475?
The Atos Unify OpenScape 4000 Platform version 10 R1 and OpenScape 4000 Manager Platform version 10 R1 are affected by CVE-2023-29475.
How can an attacker exploit CVE-2023-29475?
An unauthenticated attacker can run arbitrary commands on the platform operating system and achieve administrative access.
Where can I find more information about CVE-2023-29475?
You can find more information about CVE-2023-29475 at the following references: [1](https://networks.unify.com/security/advisories/OBSO-2303-01.pdf) and [2](https://www.news.de/technik/856806612/unify-openscape-4000-gefaehrdet-it-sicherheitswarnung-vom-bsi-und-bug-report-betroffene-systeme-und-produkte-neue-versionen-und-updates/1/).