FTP Command Injection Vulnerability in Atos Unify OpenScape Voice Trace Manager
CVE-2023-40263

8.8HIGH

Key Information:

Vendor

Atos

Vendor
CVE Published:
8 February 2024

What is CVE-2023-40263?

An issue exists in the Atos Unify OpenScape Voice Trace Manager V8 prior to version R0.9.11 which allows for the execution of unauthorized commands through authenticated FTP sessions. This vulnerability can be exploited by an attacker with valid credentials, leading to potential manipulation of system operations and compromise of data integrity. Prompt action is recommended to mitigate associated risks.

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2023-40263 : FTP Command Injection Vulnerability in Atos Unify OpenScape Voice Trace Manager