Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2023-6269

Опубликовано: 05 дек. 2023
Источник: nvd
CVSS3: 10
CVSS3: 9.8
EPSS Низкий

Описание

An argument injection vulnerability has been identified in the administrative web interface of the Atos Unify OpenScape products "Session Border Controller" (SBC) and "Branch", before version V10 R3.4.0, and OpenScape "BCF" before versions V10R10.12.00 and V10R11.05.02. This allows an unauthenticated attacker to gain root access to the appliance via SSH (scope change) and also bypass authentication for the administrative interface and gain access as an arbitrary (administrative) user.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:atos:unify_openscape_bcf:*:*:*:*:*:*:*:*
Версия от 10 (включая) до 10r10.12.00 (исключая)
cpe:2.3:a:atos:unify_openscape_branch:*:*:*:*:*:*:*:*
Версия от 10 (включая) до 10r3.4.0 (исключая)
cpe:2.3:a:atos:unify_openscape_session_border_controller:*:*:*:*:*:*:*:*
Версия от 10 (включая) до 10r3.4.0 (исключая)

EPSS

Процентиль: 63%
0.00459
Низкий

10 Critical

CVSS3

9.8 Critical

CVSS3

Дефекты

CWE-88
CWE-88

Связанные уязвимости

CVSS3: 10
github
больше 1 года назад

An argument injection vulnerability has been identified in the administrative web interface of the Atos Unify OpenScape products "Session Border Controller" (SBC) and "Branch", before version V10 R3.4.0, and OpenScape "BCF" before versions V10R10.12.00 and V10R11.05.02. This allows an unauthenticated attacker to gain root access to the appliance via SSH (scope change) and also bypass authentication for the administrative interface and gain access as an arbitrary (administrative) user.

EPSS

Процентиль: 63%
0.00459
Низкий

10 Critical

CVSS3

9.8 Critical

CVSS3

Дефекты

CWE-88
CWE-88