10

CVE-2014-2651

Unify OpenStage/OpenScape Desk Phone IP SIP before V3 R3.11.0 has an authentication bypass in the default mode of the Workpoint Interface
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
AtosOpenstage 80 Firmware Versionv3 Updater3.11.0
   AtosOpenstage 80 Version-
AtosOpenstage 80 G Firmware Versionv3 Updater3.11.0
   AtosOpenstage 80 G Version-
AtosOpenstage 60 G Firmware Versionv3 Updater3.11.0
   AtosOpenstage 60 G Version-
AtosOpenstage 60 Firmware Versionv3 Updater3.11.0
   AtosOpenstage 60 Version-
AtosOpenstage 40 Firmware Versionv3 Updater3.11.0
   AtosOpenstage 40 Version-
AtosOpenstage 40 G Firmware Versionv3 Updater3.11.0
   AtosOpenstage 40 G Version-
AtosOpenstage 20 E Firmware Versionv3 Updater3.11.0
   AtosOpenstage 20 E Version-
AtosOpenstage 20 Firmware Versionv3 Updater3.11.0
   AtosOpenstage 20 Version-
AtosOpenstage 20 G Firmware Versionv3 Updater3.11.0
   AtosOpenstage 20 G Version-
AtosOpenstage 15 Firmware Versionv3 Updater3.11.0
   AtosOpenstage 15 Version-
AtosOpenstage 15 G Firmware Versionv3 Updater3.11.0
   AtosOpenstage 15 G Version-
AtosOpenscape Desk Phone Ip 35g Firmware Versionv3 Updater3.11.0
   AtosOpenscape Desk Phone Ip 35g Version-
AtosOpenscape Desk Phone Ip 55g Firmware Versionv3 Updater3.11.0
   AtosOpenscape Desk Phone Ip 55g Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.4% 0.578
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 9.8 3.9 5.9
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvd@nist.gov 10 10 10
AV:N/AC:L/Au:N/C:C/I:C/A:C
CWE-287 Improper Authentication

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.