9.8
CVSSv3

CVE-2023-6269

Published: 05/12/2023 Updated: 13/12/2023
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 0

Vulnerability Summary

An argument injection vulnerability has been identified in the administrative web interface of the Atos Unify OpenScape products "Session Border Controller" (SBC) and "Branch", before version V10 R3.4.0, and OpenScape "BCF" prior to V10R10.12.00 and V10R11.05.02. This allows an unauthenticated malicious user to gain root access to the appliance via SSH (scope change) and also bypass authentication for the administrative interface and gain access as an arbitrary (administrative) user.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

atos unify openscape bcf

atos unify openscape branch

atos unify openscape session border controller

Exploits

Atos Unify OpenScape Session Border Controller (SBC) versions before V10 R340, Branch versions before V10 R340, and BCF versions before V10 R101200 and V10 R110502 suffer from an argument injection vulnerability that can lead to unauthenticated remote code execution and authentication bypass ...