Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2014-2651


Unify OpenStage/OpenScape Desk Phone IP SIP before V3 R3.11.0 has an authentication bypass in the default mode of the Workpoint Interface


Published

2020-01-09T13:15:10.337

Last Modified

2024-11-21T02:06:43.573

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 9.8 (CRITICAL)

CVSSv2 Vector

AV:N/AC:L/Au:N/C:C/I:C/A:C

  • Access Vector: NETWORK
  • Access Complexity: LOW
  • Authentication: NONE
  • Confidentiality Impact: COMPLETE
  • Integrity Impact: COMPLETE
  • Availability Impact: COMPLETE
Exploitability Score

10.0

Impact Score

10.0

Weaknesses
  • Type: Primary
    CWE-287

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Operating System atos openstage_80_firmware v3 Yes
Hardware atos openstage_80 - No
Operating System atos openstage_80_g_firmware v3 Yes
Hardware atos openstage_80_g - No
Operating System atos openstage_60_g_firmware v3 Yes
Hardware atos openstage_60_g - No
Operating System atos openstage_60_firmware v3 Yes
Hardware atos openstage_60 - No
Operating System atos openstage_40_firmware v3 Yes
Hardware atos openstage_40 - No
Operating System atos openstage_40_g_firmware v3 Yes
Hardware atos openstage_40_g - No
Operating System atos openstage_20_e_firmware v3 Yes
Hardware atos openstage_20_e - No
Operating System atos openstage_20_firmware v3 Yes
Hardware atos openstage_20 - No
Operating System atos openstage_20_g_firmware v3 Yes
Hardware atos openstage_20_g - No
Operating System atos openstage_15_firmware v3 Yes
Hardware atos openstage_15 - No
Operating System atos openstage_15_g_firmware v3 Yes
Hardware atos openstage_15_g - No
Operating System atos openscape_desk_phone_ip_35g_firmware v3 Yes
Hardware atos openscape_desk_phone_ip_35g - No
Operating System atos openscape_desk_phone_ip_35g_eco_firmware v3 Yes
Hardware atos openscape_desk_phone_ip_35g_eco - No
Operating System atos openscape_desk_phone_ip_55g_firmware v3 Yes
Hardware atos openscape_desk_phone_ip_55g - No

References