First published: Mon Jun 12 2023(Updated: )
Atos Unify OpenScape 4000 Assistant V10 R1 before V10 R1.42.0 and V10 R1.34.8, Assistant V10 R0, Manager V10 R1 before V10 R1.42.0 and V10 R1.34.8, and Manager V10 R0 allow command injection by authenticated users, aka OSFOURK-24036.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Atos Unify OpenScape 4000 Assistant | =10-r0 | |
Atos Unify OpenScape 4000 Assistant | =10-r1 | |
Atos Unify OpenScape 4000 Assistant | =10-r1.34.4 | |
Atos Unify OpenScape 4000 Manager | =10-r0 | |
Atos Unify OpenScape 4000 Manager | =10-r1 | |
Atos Unify OpenScape 4000 Manager | =10-r1.34.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID of this vulnerability is CVE-2023-35031.
The affected software of this vulnerability includes Atos Unify OpenScape 4000 Assistant V10 R0, V10 R1 before V10 R1.42.0 and V10 R1.34.8, and Atos Unify OpenScape 4000 Manager V10 R0, V10 R1 before V10 R1.42.0 and V10 R1.34.8.
The severity of CVE-2023-35031 is high, with a severity value of 8.8.
CVE-2023-35031 allows command injection by authenticated users.
You can find more information about CVE-2023-35031 at the following references: [Reference 1](https://networks.unify.com/security/advisories/OBSO-2305-01.pdf) and [Reference 2](https://www.news.de/technik/856882353/unify-openscape-4000-gefaehrdet-it-sicherheitswarnung-vom-bsi-und-bug-report-bekannte-schwachstellen-und-sicherheitsluecken/1/).