Arbitrary Command Execution Vulnerability in Atos Unify OpenScape 4000 Platforms
CVE-2023-29475

9.8CRITICAL

Key Information:

Vendor

Atos

Vendor
CVE Published:
6 April 2023

What is CVE-2023-29475?

A critical vulnerability in the Atos Unify OpenScape 4000 Platform and OpenScape 4000 Manager Platform 10 R1 prior to version 10 R1.34.4 allows an unauthenticated attacker to execute arbitrary commands on the underlying operating system. This flaw could result in unauthorized administrative access, posing significant risks to the platform's security and integrity. Organizations utilizing these platforms should urgently review their systems for the specified versions and apply necessary patches to mitigate potential attacks.

References

CVSS V3.1

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.