Command Injection Vulnerability in Atos Unify OpenScape 4000 Platform
CVE-2023-45356
8.8HIGH
What is CVE-2023-45356?
The OpenScape 4000 Platform and Manager Platform prior to Hotfix V10 R1.42.2 contain a command injection vulnerability that allows authenticated attackers to execute arbitrary commands on the host operating system. This flaw is accessed via the dtb pages of the platform's portal, potentially granting attackers elevated administrative privileges and compromising system integrity and confidentiality.
References
CVSS V3.1
Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved