CVE-2025-23094: Command Injection
The Platform component of Mitel OpenScape 4000 and OpenScape 4000 Manager V11 R0.22.0 through V11 R0.22.1, V10 R1.54.0 through V10 R1.54.1, and V10 R1.42.6 and earlier could allow an unauthenticated attacker to conduct a command injection attack due to insufficient parameter sanitization. A successful exploit could allow an attacker to execute arbitrary commands within the same privilege level as the web access process.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-23094?
CVE-2025-23094 has been classified with a high severity due to its potential for command injection attacks.
What are the affected versions for CVE-2025-23094?
CVE-2025-23094 affects Mitel OpenScape 4000 and OpenScape 4000 Manager versions V11 R0.22.0 to V11 R0.22.1, V10 R1.54.0 to V10 R1.54.1, and V10 R1.42.6 and earlier.
How do I fix CVE-2025-23094?
To mitigate CVE-2025-23094, it is recommended to update to the latest patched versions of Mitel OpenScape 4000 or OpenScape 4000 Manager.
What exploits are associated with CVE-2025-23094?
CVE-2025-23094 is associated with command injection attacks that can be conducted by unauthenticated attackers due to insufficient parameter sanitization.
Who is affected by CVE-2025-23094?
Organizations using vulnerable versions of Mitel OpenScape 4000 and OpenScape 4000 Manager are at risk from CVE-2025-23094.