Записи unify
15 опубликованных записей вендора unify.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 2
- С записью об исправлении
- 0 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')2
- CWE-20 Improper Input Validation1
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor1
- CWE-264 Permissions, Privileges, and Access Controls1
- CWE-331 Insufficient Entropy1
- CWE-77 Improper Neutralization of Special Elements used in a Command ('Command Injection')1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
15 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
42В плане | CVE-2000-1024Эксплойта нет | eWave ServletExec 3.0C and earlier does not restrict access to the UploadServlet Java/JSP servlet, which allows remote attackers to upload funify · ewave servletexec | Критическая10,0 | — | 5,1 % | 11 дек. 2000 г. |
40В плане | CVE-2023-36619Эксплойта нет | Atos Unify OpenScape Session Border Controller through V10 R3.01.03 allows execution of administrative scripts by unauthenticated users.unify · session border controller · CWE-20 | Критическая9,8 | — | 3,9 % | 4 окт. 2023 г. |
39Наблюдать | CVE-2014-2652Эксплойта нет | SQL injection vulnerability in OpenScape Deployment Service (DLS) before 6.x and 7.x before R1.11.3 allows remote attackers to execute arbitunify · openscape deployment service · CWE-89 | Критическая9,8 | — | 1,2 % | 19 мар. 2018 г. |
36Наблюдать | CVE-2023-36618Эксплойта нет | Atos Unify OpenScape Session Border Controller through V10 R3.01.03 allows execution of OS commands as root user by low-privileged authenticunify · session border controller · CWE-78 | Высокая8,8 | — | 3,8 % | 4 окт. 2023 г. |
35Наблюдать | CVE-2023-40263Эксплойта нет | An issue was discovered in Atos Unify OpenScape Voice Trace Manager V8 before V8 R0.9.11.unify · openscape voice trace manager · CWE-77 | Высокая8,8 | — | 1,2 % | 8 февр. 2024 г. |
32Наблюдать | CVE-2014-8422Эксплойта нет | The web-based management (WBM) interface in Unify (former Siemens) OpenStage SIP and OpenScape Desk Phone IP V3 devices before R3.32.0 generunify · openstage sip · CWE-331 | Высокая8,1 | — | 1,6 % | 12 апр. 2018 г. |
31Наблюдать | CVE-2000-0498Эксплойта нет | Unify eWave ServletExec allows a remote attacker to view source code of a JSP program by requesting a URL which provides the JSP extension iunify · ewave servletexec · CWE-178 | Высокая7,5 | — | 2,3 % | 8 июн. 2000 г. |
31Наблюдать | CVE-2014-8421Эксплойта нет | Unify (former Siemens) OpenStage SIP and OpenScape Desk Phone IP V3 devices before R3.32.0 allow remote attackers to gain super-user privileunify · openstage sip · CWE-264 | Высокая7,5 | — | 1,8 % | 12 апр. 2018 г. |
30Наблюдать | CVE-2023-48166Эксплойта нет | A directory traversal vulnerability in the SOAP Server integrated in Atos Unify OpenScape Voice V10 before V10R3.26.1 allows a remote attackunify · openscape voice · CWE-22 | Высокая7,5 | — | 1,0 % | 12 янв. 2024 г. |
24Наблюдать | CVE-2023-40262Эксплойта нет | An issue was discovered in Atos Unify OpenScape Voice Trace Manager V8 before V8 R0.9.11.unify · openscape voice trace manager · CWE-79 | Средняя6,1 | — | 0,3 % | 8 февр. 2024 г. |
23Наблюдать | CVE-2000-1025Proof of concept | eWave ServletExec JSP/Java servlet engine, versions 3.0C and earlier, allows remote attackers to cause a denial of service via a URL that counify · ewave servletexec | Средняя5,0 | — | 8,5 % | 11 дек. 2000 г. |
23Наблюдать | CVE-2015-8251Эксплойта нет | OpenStage 60 and OpenScape Desk Phone IP 55G SIP V3, OpenStage 15, 20E, 20 and 40 and OpenScape Desk Phone IP 35G SIP V3, OpenScape Desk Phounify · openstage 60 firmware · CWE-200 | Средняя5,9 | — | 1,3 % | 25 сент. 2017 г. |
21Наблюдать | CVE-2000-1114Proof of concept | Unify ServletExec AS v3.0C allows remote attackers to read source code for JSP pages via an HTTP request that ends with characters such as "unify · ewave servletexec | Средняя5,0 | — | 2,9 % | 9 янв. 2001 г. |
19Наблюдать | CVE-2014-9563Эксплойта нет | CRLF injection vulnerability in the web-based management (WBM) interface in Unify (former Siemens) OpenStage SIP and OpenScape Desk Phone IPunify · openstage sip · CWE-93 | Средняя4,9 | — | 1,2 % | 12 апр. 2018 г. |
17Наблюдать | CVE-2023-40264Эксплойта нет | An issue was discovered in Atos Unify OpenScape Voice Trace Manager V8 before V8 R0.9.11.unify · openscape voice trace manager · CWE-22 | Средняя4,3 | — | 0,5 % | 8 февр. 2024 г. |
- CVE-2000-102442В плане
eWave ServletExec 3.0C and earlier does not restrict access to the UploadServlet Java/JSP servlet, which allows remote attackers to upload f
КритическаяCVSS 10,0Эксплойта нетEPSS 5 %unify · ewave servletexec11 дек. 2000 г.
- CVE-2023-3661940В плане
Atos Unify OpenScape Session Border Controller through V10 R3.01.03 allows execution of administrative scripts by unauthenticated users.
КритическаяCVSS 9,8Эксплойта нетEPSS 4 %unify · session border controller4 окт. 2023 г.
- CVE-2014-265239Наблюдать
SQL injection vulnerability in OpenScape Deployment Service (DLS) before 6.x and 7.x before R1.11.3 allows remote attackers to execute arbit
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %unify · openscape deployment service19 мар. 2018 г.
- CVE-2023-3661836Наблюдать
Atos Unify OpenScape Session Border Controller through V10 R3.01.03 allows execution of OS commands as root user by low-privileged authentic
ВысокаяCVSS 8,8Эксплойта нетEPSS 4 %unify · session border controller4 окт. 2023 г.
- CVE-2023-4026335Наблюдать
An issue was discovered in Atos Unify OpenScape Voice Trace Manager V8 before V8 R0.9.11.
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %unify · openscape voice trace manager8 февр. 2024 г.
- CVE-2014-842232Наблюдать
The web-based management (WBM) interface in Unify (former Siemens) OpenStage SIP and OpenScape Desk Phone IP V3 devices before R3.32.0 gener
ВысокаяCVSS 8,1Эксплойта нетEPSS 2 %unify · openstage sip12 апр. 2018 г.
- CVE-2000-049831Наблюдать
Unify eWave ServletExec allows a remote attacker to view source code of a JSP program by requesting a URL which provides the JSP extension i
ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %unify · ewave servletexec8 июн. 2000 г.
- CVE-2014-842131Наблюдать
Unify (former Siemens) OpenStage SIP and OpenScape Desk Phone IP V3 devices before R3.32.0 allow remote attackers to gain super-user privile
ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %unify · openstage sip12 апр. 2018 г.
- CVE-2023-4816630Наблюдать
A directory traversal vulnerability in the SOAP Server integrated in Atos Unify OpenScape Voice V10 before V10R3.26.1 allows a remote attack
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %unify · openscape voice12 янв. 2024 г.
- CVE-2023-4026224Наблюдать
An issue was discovered in Atos Unify OpenScape Voice Trace Manager V8 before V8 R0.9.11.
СредняяCVSS 6,1Эксплойта нетEPSS 0 %unify · openscape voice trace manager8 февр. 2024 г.
- CVE-2000-102523Наблюдать
eWave ServletExec JSP/Java servlet engine, versions 3.0C and earlier, allows remote attackers to cause a denial of service via a URL that co
СредняяCVSS 5,0Proof of conceptEPSS 8 %unify · ewave servletexec11 дек. 2000 г.
- CVE-2015-825123Наблюдать
OpenStage 60 and OpenScape Desk Phone IP 55G SIP V3, OpenStage 15, 20E, 20 and 40 and OpenScape Desk Phone IP 35G SIP V3, OpenScape Desk Pho
СредняяCVSS 5,9Эксплойта нетEPSS 1 %unify · openstage 60 firmware25 сент. 2017 г.
- CVE-2000-111421Наблюдать
Unify ServletExec AS v3.0C allows remote attackers to read source code for JSP pages via an HTTP request that ends with characters such as "
СредняяCVSS 5,0Proof of conceptEPSS 3 %unify · ewave servletexec9 янв. 2001 г.
- CVE-2014-956319Наблюдать
CRLF injection vulnerability in the web-based management (WBM) interface in Unify (former Siemens) OpenStage SIP and OpenScape Desk Phone IP
СредняяCVSS 4,9Эксплойта нетEPSS 1 %unify · openstage sip12 апр. 2018 г.
- CVE-2023-4026417Наблюдать
An issue was discovered in Atos Unify OpenScape Voice Trace Manager V8 before V8 R0.9.11.
СредняяCVSS 4,3Эксплойта нетEPSS 0 %unify · openscape voice trace manager8 февр. 2024 г.