Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-xx5w-j8g7-4v5f

Опубликовано: 05 дек. 2023
Источник: github
Github: Не прошло ревью
CVSS3: 10

Описание

An argument injection vulnerability has been identified in the administrative web interface of the Atos Unify OpenScape products "Session Border Controller" (SBC) and "Branch", before version V10 R3.4.0, and OpenScape "BCF" before versions V10R10.12.00 and V10R11.05.02. This allows an unauthenticated attacker to gain root access to the appliance via SSH (scope change) and also bypass authentication for the administrative interface and gain access as an arbitrary (administrative) user.

An argument injection vulnerability has been identified in the administrative web interface of the Atos Unify OpenScape products "Session Border Controller" (SBC) and "Branch", before version V10 R3.4.0, and OpenScape "BCF" before versions V10R10.12.00 and V10R11.05.02. This allows an unauthenticated attacker to gain root access to the appliance via SSH (scope change) and also bypass authentication for the administrative interface and gain access as an arbitrary (administrative) user.

EPSS

Процентиль: 63%
0.00459
Низкий

10 Critical

CVSS3

Дефекты

CWE-88

Связанные уязвимости

CVSS3: 10
nvd
больше 1 года назад

An argument injection vulnerability has been identified in the administrative web interface of the Atos Unify OpenScape products "Session Border Controller" (SBC) and "Branch", before version V10 R3.4.0, and OpenScape "BCF" before versions V10R10.12.00 and V10R11.05.02. This allows an unauthenticated attacker to gain root access to the appliance via SSH (scope change) and also bypass authentication for the administrative interface and gain access as an arbitrary (administrative) user.

EPSS

Процентиль: 63%
0.00459
Низкий

10 Critical

CVSS3

Дефекты

CWE-88