9.8
CVE-2022-46404
- EPSS 10.91%
- Veröffentlicht 13.12.2022 21:15:11
- Zuletzt bearbeitet 22.04.2025 15:16:07
- Quelle cve@mitre.org
- CVE-Watchlists
- Unerledigt
A command injection vulnerability has been identified in Atos Unify OpenScape 4000 Assistant and Unify OpenScape 4000 Manager (8 before R2.22.18, 10 before 0.28.13, and 10 R1 before R1.34.4) that may allow an unauthenticated attacker to upload arbitrary files and achieve administrative access to the system.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Atos ≫ Unify Openscape 4000 Assistant Version8 Update-
Atos ≫ Unify Openscape 4000 Assistant Version10 Update-
Atos ≫ Unify Openscape 4000 Manager Version8 Update-
Atos ≫ Unify Openscape 4000 Manager Version10 Update-
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 10.91% | 0.931 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 9.8 | 3.9 | 5.9 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
|
| cve@mitre.org | 9.8 | 3.9 | 5.9 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
|
CWE-77 Improper Neutralization of Special Elements used in a Command ('Command Injection')
The product constructs all or part of a command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended command when it is sent to a downstream component.