10

CVE-2014-2650

Unify OpenStage / OpenScape Desk Phone IP before V3 R3.11.0 SIP has an OS command injection vulnerability in the web based management interface
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
AtosOpenstage 80 Firmware Versionv3 Updater3.11.0
   AtosOpenstage 80 Version-
AtosOpenstage 80 G Firmware Versionv3 Updater3.11.0
   AtosOpenstage 80 G Version-
AtosOpenstage 60 G Firmware Versionv3 Updater3.11.0
   AtosOpenstage 60 G Version-
AtosOpenstage 60 Firmware Versionv3 Updater3.11.0
   AtosOpenstage 60 Version-
AtosOpenstage 40 Firmware Versionv3 Updater3.11.0
   AtosOpenstage 40 Version-
AtosOpenstage 40 G Firmware Versionv3 Updater3.11.0
   AtosOpenstage 40 G Version-
AtosOpenstage 20 E Firmware Versionv3 Updater3.11.0
   AtosOpenstage 20 E Version-
AtosOpenstage 20 Firmware Versionv3 Updater3.11.0
   AtosOpenstage 20 Version-
AtosOpenstage 20 G Firmware Versionv3 Updater3.11.0
   AtosOpenstage 20 G Version-
AtosOpenstage 15 Firmware Versionv3 Updater3.11.0
   AtosOpenstage 15 Version-
AtosOpenstage 15 G Firmware Versionv3 Updater3.11.0
   AtosOpenstage 15 G Version-
AtosOpenstage 5 Firmware Versionv3 Updater3.11.0
   AtosOpenstage 5 Version-
AtosOpenscape Desk Phone Ip 35g Firmware Versionv3 Updater3.11.0
   AtosOpenscape Desk Phone Ip 35g Version-
AtosOpenscape Desk Phone Ip 55g Firmware Versionv3 Updater3.11.0
   AtosOpenscape Desk Phone Ip 55g Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 5.37% 0.897
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 9.8 3.9 5.9
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvd@nist.gov 10 10 10
AV:N/AC:L/Au:N/C:C/I:C/A:C
CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')

The product constructs all or part of an OS command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended OS command when it is sent to a downstream component.