6.8
CVSSv2

CVE-2014-8422

Published: 12/04/2018 Updated: 09/09/2021
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
CVSS v3 Base Score: 8.1 | Impact Score: 5.9 | Exploitability Score: 2.2
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

The web-based management (WBM) interface in Unify (former Siemens) OpenStage SIP and OpenScape Desk Phone IP V3 devices before R3.32.0 generates session cookies with insufficient entropy, which makes it easier for remote malicious users to hijack sessions via a brute-force attack.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

unify openstage sip

unify openscape desk phone ip sip