CVE Feed

    Dashboard / CVE / CVE-2014-2650

    CVE-2014-2650

    Unify OpenStage / OpenScape Desk Phone IP before V3 R3.11.0 SIP has an OS command injection vulnerability in the web based management interface

    Published:Jan 9, 2020
    Last Modified:Nov 21, 2024
    EPS:Jan 9, 2020
    EPSS Score:0.05268
    CVSS Score:9.8

    Affected Products

    Vendor
    Atos
    Product
    Openscape Desk Phone Ip 35g
    Vendor
    Atos
    Product
    Openscape Desk Phone Ip 35g Eco
    Vendor
    Atos
    Product
    Openscape Desk Phone Ip 35g Eco Firmware
    Vendor
    Atos
    Product
    Openscape Desk Phone Ip 35g Firmware
    Vendor
    Atos
    Product
    Openscape Desk Phone Ip 55g
    Vendor
    Atos
    Product
    Openscape Desk Phone Ip 55g Firmware
    Vendor
    Atos
    Product
    Openstage 15
    Vendor
    Atos
    Product
    Openstage 15 Firmware
    Vendor
    Atos
    Product
    Openstage 15 G
    Vendor
    Atos
    Product
    Openstage 15 G Firmware
    Vendor
    Atos
    Product
    Openstage 20
    Vendor
    Atos
    Product
    Openstage 20 E
    Vendor
    Atos
    Product
    Openstage 20 E Firmware
    Vendor
    Atos
    Product
    Openstage 20 Firmware
    Vendor
    Atos
    Product
    Openstage 20 G
    Vendor
    Atos
    Product
    Openstage 20 G Firmware
    Vendor
    Atos
    Product
    Openstage 40
    Vendor
    Atos
    Product
    Openstage 40 Firmware
    Vendor
    Atos
    Product
    Openstage 40 G
    Vendor
    Atos
    Product
    Openstage 40 G Firmware
    Vendor
    Atos
    Product
    Openstage 5
    Vendor
    Atos
    Product
    Openstage 5 Firmware
    Vendor
    Atos
    Product
    Openstage 60
    Vendor
    Atos
    Product
    Openstage 60 Firmware
    Vendor
    Atos
    Product
    Openstage 60 G
    Vendor
    Atos
    Product
    Openstage 60 G Firmware
    Vendor
    Atos
    Product
    Openstage 80
    Vendor
    Atos
    Product
    Openstage 80 Firmware
    Vendor
    Atos
    Product
    Openstage 80 G
    Vendor
    Atos
    Product
    Openstage 80 G Firmware

    Exploits

    No exploit reference

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High