CVE-2023-35034

Atos Unify OpenScape 4000 Assistant V10 R1 before V10 R1.42.0 and V10 R1.34.8 and Manager V10 R1 before V10 R1.42.0 and V10 R1.34.8 allow remote code execution by unauthenticated users, aka OSFOURK-24033.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:atos:unify_openscape_4000_assistant:10:r1:*:*:*:*:*:*
cpe:2.3:a:atos:unify_openscape_4000_assistant:10:r1.34.4:*:*:*:*:*:*
cpe:2.3:a:atos:unify_openscape_4000_manager:10:r1:*:*:*:*:*:*
cpe:2.3:a:atos:unify_openscape_4000_manager:10:r1.34.4:*:*:*:*:*:*

History

06 Jan 2025, 18:15

Type Values Removed Values Added
CWE CWE-94

21 Nov 2024, 08:07

Type Values Removed Values Added
References () https://networks.unify.com/security/advisories/OBSO-2305-01.pdf - Vendor Advisory () https://networks.unify.com/security/advisories/OBSO-2305-01.pdf - Vendor Advisory
References () https://www.news.de/technik/856882353/unify-openscape-4000-gefaehrdet-it-sicherheitswarnung-vom-bsi-und-bug-report-bekannte-schwachstellen-und-sicherheitsluecken/1/ - Press/Media Coverage () https://www.news.de/technik/856882353/unify-openscape-4000-gefaehrdet-it-sicherheitswarnung-vom-bsi-und-bug-report-bekannte-schwachstellen-und-sicherheitsluecken/1/ - Press/Media Coverage

16 Jun 2023, 19:31

Type Values Removed Values Added
References (MISC) https://www.news.de/technik/856882353/unify-openscape-4000-gefaehrdet-it-sicherheitswarnung-vom-bsi-und-bug-report-bekannte-schwachstellen-und-sicherheitsluecken/1/ - (MISC) https://www.news.de/technik/856882353/unify-openscape-4000-gefaehrdet-it-sicherheitswarnung-vom-bsi-und-bug-report-bekannte-schwachstellen-und-sicherheitsluecken/1/ - Press/Media Coverage
References (MISC) https://networks.unify.com/security/advisories/OBSO-2305-01.pdf - (MISC) https://networks.unify.com/security/advisories/OBSO-2305-01.pdf - Vendor Advisory
First Time Atos
Atos unify Openscape 4000 Manager
Atos unify Openscape 4000 Assistant
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 9.8
CWE NVD-CWE-noinfo
CPE cpe:2.3:a:atos:unify_openscape_4000_assistant:10:r1.34.4:*:*:*:*:*:*
cpe:2.3:a:atos:unify_openscape_4000_assistant:10:r1:*:*:*:*:*:*
cpe:2.3:a:atos:unify_openscape_4000_manager:10:r1:*:*:*:*:*:*
cpe:2.3:a:atos:unify_openscape_4000_manager:10:r1.34.4:*:*:*:*:*:*

12 Jun 2023, 02:15

Type Values Removed Values Added
New CVE

Information

Published : 2023-06-12 02:15

Updated : 2025-01-06 18:15


NVD link : CVE-2023-35034

Mitre link : CVE-2023-35034

CVE.ORG link : CVE-2023-35034


JSON object : View

Products Affected

atos

  • unify_openscape_4000_manager
  • unify_openscape_4000_assistant
CWE
NVD-CWE-noinfo CWE-94

Improper Control of Generation of Code ('Code Injection')