605
VMScore

CVE-2014-8422

Published: 12/04/2018 Updated: 09/09/2021
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
CVSS v3 Base Score: 8.1 | Impact Score: 5.9 | Exploitability Score: 2.2
VMScore: 605
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

The web-based management (WBM) interface in Unify (former Siemens) OpenStage SIP and OpenScape Desk Phone IP V3 devices before R3.32.0 generates session cookies with insufficient entropy, which makes it easier for remote malicious users to hijack sessions via a brute-force attack.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

unify openstage_sip

unify openscape_desk_phone_ip_sip