unify kayıtları
unify üreticisine ait 15 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 2
- Düzeltme kaydı olan
- %0
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')2
- CWE-20 Improper Input Validation1
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor1
- CWE-264 Permissions, Privileges, and Access Controls1
- CWE-331 Insufficient Entropy1
- CWE-77 Improper Neutralization of Special Elements used in a Command ('Command Injection')1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
15 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
42Planlayın | CVE-2000-1024İstismar yok | eWave ServletExec 3.0C and earlier does not restrict access to the UploadServlet Java/JSP servlet, which allows remote attackers to upload funify · ewave servletexec | Kritik10,0 | — | %5,1 | 11 Ara 2000 |
40Planlayın | CVE-2023-36619İstismar yok | Atos Unify OpenScape Session Border Controller through V10 R3.01.03 allows execution of administrative scripts by unauthenticated users.unify · session border controller · CWE-20 | Kritik9,8 | — | %3,9 | 4 Eki 2023 |
39İzleyin | CVE-2014-2652İstismar yok | SQL injection vulnerability in OpenScape Deployment Service (DLS) before 6.x and 7.x before R1.11.3 allows remote attackers to execute arbitunify · openscape deployment service · CWE-89 | Kritik9,8 | — | %1,2 | 19 Mar 2018 |
36İzleyin | CVE-2023-36618İstismar yok | Atos Unify OpenScape Session Border Controller through V10 R3.01.03 allows execution of OS commands as root user by low-privileged authenticunify · session border controller · CWE-78 | Yüksek8,8 | — | %3,8 | 4 Eki 2023 |
35İzleyin | CVE-2023-40263İstismar yok | An issue was discovered in Atos Unify OpenScape Voice Trace Manager V8 before V8 R0.9.11.unify · openscape voice trace manager · CWE-77 | Yüksek8,8 | — | %1,2 | 8 Şub 2024 |
32İzleyin | CVE-2014-8422İstismar yok | The web-based management (WBM) interface in Unify (former Siemens) OpenStage SIP and OpenScape Desk Phone IP V3 devices before R3.32.0 generunify · openstage sip · CWE-331 | Yüksek8,1 | — | %1,6 | 12 Nis 2018 |
31İzleyin | CVE-2000-0498İstismar yok | Unify eWave ServletExec allows a remote attacker to view source code of a JSP program by requesting a URL which provides the JSP extension iunify · ewave servletexec · CWE-178 | Yüksek7,5 | — | %2,3 | 8 Haz 2000 |
31İzleyin | CVE-2014-8421İstismar yok | Unify (former Siemens) OpenStage SIP and OpenScape Desk Phone IP V3 devices before R3.32.0 allow remote attackers to gain super-user privileunify · openstage sip · CWE-264 | Yüksek7,5 | — | %1,8 | 12 Nis 2018 |
30İzleyin | CVE-2023-48166İstismar yok | A directory traversal vulnerability in the SOAP Server integrated in Atos Unify OpenScape Voice V10 before V10R3.26.1 allows a remote attackunify · openscape voice · CWE-22 | Yüksek7,5 | — | %1,0 | 12 Oca 2024 |
24İzleyin | CVE-2023-40262İstismar yok | An issue was discovered in Atos Unify OpenScape Voice Trace Manager V8 before V8 R0.9.11.unify · openscape voice trace manager · CWE-79 | Orta6,1 | — | %0,3 | 8 Şub 2024 |
23İzleyin | CVE-2000-1025Kavram kanıtı | eWave ServletExec JSP/Java servlet engine, versions 3.0C and earlier, allows remote attackers to cause a denial of service via a URL that counify · ewave servletexec | Orta5,0 | — | %8,5 | 11 Ara 2000 |
23İzleyin | CVE-2015-8251İstismar yok | OpenStage 60 and OpenScape Desk Phone IP 55G SIP V3, OpenStage 15, 20E, 20 and 40 and OpenScape Desk Phone IP 35G SIP V3, OpenScape Desk Phounify · openstage 60 firmware · CWE-200 | Orta5,9 | — | %1,3 | 25 Eyl 2017 |
21İzleyin | CVE-2000-1114Kavram kanıtı | Unify ServletExec AS v3.0C allows remote attackers to read source code for JSP pages via an HTTP request that ends with characters such as "unify · ewave servletexec | Orta5,0 | — | %2,9 | 9 Oca 2001 |
19İzleyin | CVE-2014-9563İstismar yok | CRLF injection vulnerability in the web-based management (WBM) interface in Unify (former Siemens) OpenStage SIP and OpenScape Desk Phone IPunify · openstage sip · CWE-93 | Orta4,9 | — | %1,2 | 12 Nis 2018 |
17İzleyin | CVE-2023-40264İstismar yok | An issue was discovered in Atos Unify OpenScape Voice Trace Manager V8 before V8 R0.9.11.unify · openscape voice trace manager · CWE-22 | Orta4,3 | — | %0,5 | 8 Şub 2024 |
- CVE-2000-102442Planlayın
eWave ServletExec 3.0C and earlier does not restrict access to the UploadServlet Java/JSP servlet, which allows remote attackers to upload f
KritikCVSS 10,0İstismar yokEPSS %5unify · ewave servletexec11 Ara 2000
- CVE-2023-3661940Planlayın
Atos Unify OpenScape Session Border Controller through V10 R3.01.03 allows execution of administrative scripts by unauthenticated users.
KritikCVSS 9,8İstismar yokEPSS %4unify · session border controller4 Eki 2023
- CVE-2014-265239İzleyin
SQL injection vulnerability in OpenScape Deployment Service (DLS) before 6.x and 7.x before R1.11.3 allows remote attackers to execute arbit
KritikCVSS 9,8İstismar yokEPSS %1unify · openscape deployment service19 Mar 2018
- CVE-2023-3661836İzleyin
Atos Unify OpenScape Session Border Controller through V10 R3.01.03 allows execution of OS commands as root user by low-privileged authentic
YüksekCVSS 8,8İstismar yokEPSS %4unify · session border controller4 Eki 2023
- CVE-2023-4026335İzleyin
An issue was discovered in Atos Unify OpenScape Voice Trace Manager V8 before V8 R0.9.11.
YüksekCVSS 8,8İstismar yokEPSS %1unify · openscape voice trace manager8 Şub 2024
- CVE-2014-842232İzleyin
The web-based management (WBM) interface in Unify (former Siemens) OpenStage SIP and OpenScape Desk Phone IP V3 devices before R3.32.0 gener
YüksekCVSS 8,1İstismar yokEPSS %2unify · openstage sip12 Nis 2018
- CVE-2000-049831İzleyin
Unify eWave ServletExec allows a remote attacker to view source code of a JSP program by requesting a URL which provides the JSP extension i
YüksekCVSS 7,5İstismar yokEPSS %2unify · ewave servletexec8 Haz 2000
- CVE-2014-842131İzleyin
Unify (former Siemens) OpenStage SIP and OpenScape Desk Phone IP V3 devices before R3.32.0 allow remote attackers to gain super-user privile
YüksekCVSS 7,5İstismar yokEPSS %2unify · openstage sip12 Nis 2018
- CVE-2023-4816630İzleyin
A directory traversal vulnerability in the SOAP Server integrated in Atos Unify OpenScape Voice V10 before V10R3.26.1 allows a remote attack
YüksekCVSS 7,5İstismar yokEPSS %1unify · openscape voice12 Oca 2024
- CVE-2023-4026224İzleyin
An issue was discovered in Atos Unify OpenScape Voice Trace Manager V8 before V8 R0.9.11.
OrtaCVSS 6,1İstismar yokEPSS %0unify · openscape voice trace manager8 Şub 2024
- CVE-2000-102523İzleyin
eWave ServletExec JSP/Java servlet engine, versions 3.0C and earlier, allows remote attackers to cause a denial of service via a URL that co
OrtaCVSS 5,0Kavram kanıtıEPSS %8unify · ewave servletexec11 Ara 2000
- CVE-2015-825123İzleyin
OpenStage 60 and OpenScape Desk Phone IP 55G SIP V3, OpenStage 15, 20E, 20 and 40 and OpenScape Desk Phone IP 35G SIP V3, OpenScape Desk Pho
OrtaCVSS 5,9İstismar yokEPSS %1unify · openstage 60 firmware25 Eyl 2017
- CVE-2000-111421İzleyin
Unify ServletExec AS v3.0C allows remote attackers to read source code for JSP pages via an HTTP request that ends with characters such as "
OrtaCVSS 5,0Kavram kanıtıEPSS %3unify · ewave servletexec9 Oca 2001
- CVE-2014-956319İzleyin
CRLF injection vulnerability in the web-based management (WBM) interface in Unify (former Siemens) OpenStage SIP and OpenScape Desk Phone IP
OrtaCVSS 4,9İstismar yokEPSS %1unify · openstage sip12 Nis 2018
- CVE-2023-4026417İzleyin
An issue was discovered in Atos Unify OpenScape Voice Trace Manager V8 before V8 R0.9.11.
OrtaCVSS 4,3İstismar yokEPSS %0unify · openscape voice trace manager8 Şub 2024