unify records
15 published records for vendor unify.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 2
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')2
- CWE-20 Improper Input Validation1
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor1
- CWE-264 Permissions, Privileges, and Access Controls1
- CWE-331 Insufficient Entropy1
- CWE-77 Improper Neutralization of Special Elements used in a Command ('Command Injection')1
The weakness classes this vendor ships most often: where to look.
CWEAll records
15 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
42Plan | CVE-2000-1024No exploit | eWave ServletExec 3.0C and earlier does not restrict access to the UploadServlet Java/JSP servlet, which allows remote attackers to upload funify · ewave servletexec | Critical10.0 | — | 5.1% | Dec 11, 2000 |
40Plan | CVE-2023-36619No exploit | Atos Unify OpenScape Session Border Controller through V10 R3.01.03 allows execution of administrative scripts by unauthenticated users.unify · session border controller · CWE-20 | Critical9.8 | — | 3.9% | Oct 4, 2023 |
39Monitor | CVE-2014-2652No exploit | SQL injection vulnerability in OpenScape Deployment Service (DLS) before 6.x and 7.x before R1.11.3 allows remote attackers to execute arbitunify · openscape deployment service · CWE-89 | Critical9.8 | — | 1.2% | Mar 19, 2018 |
36Monitor | CVE-2023-36618No exploit | Atos Unify OpenScape Session Border Controller through V10 R3.01.03 allows execution of OS commands as root user by low-privileged authenticunify · session border controller · CWE-78 | High8.8 | — | 3.8% | Oct 4, 2023 |
35Monitor | CVE-2023-40263No exploit | An issue was discovered in Atos Unify OpenScape Voice Trace Manager V8 before V8 R0.9.11.unify · openscape voice trace manager · CWE-77 | High8.8 | — | 1.2% | Feb 8, 2024 |
32Monitor | CVE-2014-8422No exploit | The web-based management (WBM) interface in Unify (former Siemens) OpenStage SIP and OpenScape Desk Phone IP V3 devices before R3.32.0 generunify · openstage sip · CWE-331 | High8.1 | — | 1.6% | Apr 12, 2018 |
31Monitor | CVE-2000-0498No exploit | Unify eWave ServletExec allows a remote attacker to view source code of a JSP program by requesting a URL which provides the JSP extension iunify · ewave servletexec · CWE-178 | High7.5 | — | 2.3% | Jun 8, 2000 |
31Monitor | CVE-2014-8421No exploit | Unify (former Siemens) OpenStage SIP and OpenScape Desk Phone IP V3 devices before R3.32.0 allow remote attackers to gain super-user privileunify · openstage sip · CWE-264 | High7.5 | — | 1.8% | Apr 12, 2018 |
30Monitor | CVE-2023-48166No exploit | A directory traversal vulnerability in the SOAP Server integrated in Atos Unify OpenScape Voice V10 before V10R3.26.1 allows a remote attackunify · openscape voice · CWE-22 | High7.5 | — | 1.0% | Jan 12, 2024 |
24Monitor | CVE-2023-40262No exploit | An issue was discovered in Atos Unify OpenScape Voice Trace Manager V8 before V8 R0.9.11.unify · openscape voice trace manager · CWE-79 | Medium6.1 | — | 0.3% | Feb 8, 2024 |
23Monitor | CVE-2000-1025Proof of concept | eWave ServletExec JSP/Java servlet engine, versions 3.0C and earlier, allows remote attackers to cause a denial of service via a URL that counify · ewave servletexec | Medium5.0 | — | 8.5% | Dec 11, 2000 |
23Monitor | CVE-2015-8251No exploit | OpenStage 60 and OpenScape Desk Phone IP 55G SIP V3, OpenStage 15, 20E, 20 and 40 and OpenScape Desk Phone IP 35G SIP V3, OpenScape Desk Phounify · openstage 60 firmware · CWE-200 | Medium5.9 | — | 1.3% | Sep 25, 2017 |
21Monitor | CVE-2000-1114Proof of concept | Unify ServletExec AS v3.0C allows remote attackers to read source code for JSP pages via an HTTP request that ends with characters such as "unify · ewave servletexec | Medium5.0 | — | 2.9% | Jan 9, 2001 |
19Monitor | CVE-2014-9563No exploit | CRLF injection vulnerability in the web-based management (WBM) interface in Unify (former Siemens) OpenStage SIP and OpenScape Desk Phone IPunify · openstage sip · CWE-93 | Medium4.9 | — | 1.2% | Apr 12, 2018 |
17Monitor | CVE-2023-40264No exploit | An issue was discovered in Atos Unify OpenScape Voice Trace Manager V8 before V8 R0.9.11.unify · openscape voice trace manager · CWE-22 | Medium4.3 | — | 0.5% | Feb 8, 2024 |
- CVE-2000-102442Plan
eWave ServletExec 3.0C and earlier does not restrict access to the UploadServlet Java/JSP servlet, which allows remote attackers to upload f
CriticalCVSS 10.0No exploitEPSS 5%unify · ewave servletexecDec 11, 2000
- CVE-2023-3661940Plan
Atos Unify OpenScape Session Border Controller through V10 R3.01.03 allows execution of administrative scripts by unauthenticated users.
CriticalCVSS 9.8No exploitEPSS 4%unify · session border controllerOct 4, 2023
- CVE-2014-265239Monitor
SQL injection vulnerability in OpenScape Deployment Service (DLS) before 6.x and 7.x before R1.11.3 allows remote attackers to execute arbit
CriticalCVSS 9.8No exploitEPSS 1%unify · openscape deployment serviceMar 19, 2018
- CVE-2023-3661836Monitor
Atos Unify OpenScape Session Border Controller through V10 R3.01.03 allows execution of OS commands as root user by low-privileged authentic
HighCVSS 8.8No exploitEPSS 4%unify · session border controllerOct 4, 2023
- CVE-2023-4026335Monitor
An issue was discovered in Atos Unify OpenScape Voice Trace Manager V8 before V8 R0.9.11.
HighCVSS 8.8No exploitEPSS 1%unify · openscape voice trace managerFeb 8, 2024
- CVE-2014-842232Monitor
The web-based management (WBM) interface in Unify (former Siemens) OpenStage SIP and OpenScape Desk Phone IP V3 devices before R3.32.0 gener
HighCVSS 8.1No exploitEPSS 2%unify · openstage sipApr 12, 2018
- CVE-2000-049831Monitor
Unify eWave ServletExec allows a remote attacker to view source code of a JSP program by requesting a URL which provides the JSP extension i
HighCVSS 7.5No exploitEPSS 2%unify · ewave servletexecJun 8, 2000
- CVE-2014-842131Monitor
Unify (former Siemens) OpenStage SIP and OpenScape Desk Phone IP V3 devices before R3.32.0 allow remote attackers to gain super-user privile
HighCVSS 7.5No exploitEPSS 2%unify · openstage sipApr 12, 2018
- CVE-2023-4816630Monitor
A directory traversal vulnerability in the SOAP Server integrated in Atos Unify OpenScape Voice V10 before V10R3.26.1 allows a remote attack
HighCVSS 7.5No exploitEPSS 1%unify · openscape voiceJan 12, 2024
- CVE-2023-4026224Monitor
An issue was discovered in Atos Unify OpenScape Voice Trace Manager V8 before V8 R0.9.11.
MediumCVSS 6.1No exploitEPSS 0%unify · openscape voice trace managerFeb 8, 2024
- CVE-2000-102523Monitor
eWave ServletExec JSP/Java servlet engine, versions 3.0C and earlier, allows remote attackers to cause a denial of service via a URL that co
MediumCVSS 5.0Proof of conceptEPSS 8%unify · ewave servletexecDec 11, 2000
- CVE-2015-825123Monitor
OpenStage 60 and OpenScape Desk Phone IP 55G SIP V3, OpenStage 15, 20E, 20 and 40 and OpenScape Desk Phone IP 35G SIP V3, OpenScape Desk Pho
MediumCVSS 5.9No exploitEPSS 1%unify · openstage 60 firmwareSep 25, 2017
- CVE-2000-111421Monitor
Unify ServletExec AS v3.0C allows remote attackers to read source code for JSP pages via an HTTP request that ends with characters such as "
MediumCVSS 5.0Proof of conceptEPSS 3%unify · ewave servletexecJan 9, 2001
- CVE-2014-956319Monitor
CRLF injection vulnerability in the web-based management (WBM) interface in Unify (former Siemens) OpenStage SIP and OpenScape Desk Phone IP
MediumCVSS 4.9No exploitEPSS 1%unify · openstage sipApr 12, 2018
- CVE-2023-4026417Monitor
An issue was discovered in Atos Unify OpenScape Voice Trace Manager V8 before V8 R0.9.11.
MediumCVSS 4.3No exploitEPSS 0%unify · openscape voice trace managerFeb 8, 2024