Unify develops telecommunications and unified communications infrastructure products, including IP desk phones, call servers, and middleware platforms such as the OpenStage and OpenScape lines, which occupy critical roles in enterprise communications networks. Vulnerabilities affecting the vendor skew toward serious outcomes and frequently acquire public exploit code; the exposure recurs across its product portfolio through weakness classes centered on path traversal, improper input validation, and exposure of sensitive information that are characteristic of server and middleware software exposed to untrusted network input. Current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Unify over time
Signals from CVEs in this vendor scope (15 CVEs).
15 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2014-2652CRITICAL SQL injection vulnerability in OpenScape Deployment Service (DLS) before 6.x and 7.x before R1.11.3 allows remote attackers to execute arbitrary SQL commands via unspecified vector | Mar 19, 2018 | 9.8 | 31 | NO | NO |
CVE-2023-36619CRITICAL Atos Unify OpenScape Session Border Controller through V10 R3.01.03 allows execution of administrative scripts by unauthenticated users. | Oct 4, 2023 | 9.8 | 27 | NO | NO |
CVE-2000-1024HIGH eWave ServletExec 3.0C and earlier does not restrict access to the UploadServlet Java/JSP servlet, which allows remote attackers to upload files and execute arbitrary commands. | Dec 11, 2000 | 10.0 | 26 | NO | NO |
CVE-2023-36618HIGH Atos Unify OpenScape Session Border Controller through V10 R3.01.03 allows execution of OS commands as root user by low-privileged authenticated users. | Oct 4, 2023 | 8.8 | 25 | NO | NO |
CVE-2000-1025MEDIUM eWave ServletExec JSP/Java servlet engine, versions 3.0C and earlier, allows remote attackers to cause a denial of service via a URL that contains the "/servlet/" string, which inv | Dec 11, 2000 | 5.0 | 25 | NO | YES |
CVE-2023-40263HIGH An issue was discovered in Atos Unify OpenScape Voice Trace Manager V8 before V8 R0.9.11. It allows authenticated command injection via ftp. | Feb 8, 2024 | 8.8 | 24 | NO | NO |
CVE-2023-48166HIGH A directory traversal vulnerability in the SOAP Server integrated in Atos Unify OpenScape Voice V10 before V10R3.26.1 allows a remote attacker to view the contents of arbitrary fil | Jan 12, 2024 | 7.5 | 23 | NO | NO |
CVE-2000-1114MEDIUM Unify ServletExec AS v3.0C allows remote attackers to read source code for JSP pages via an HTTP request that ends with characters such as ".", or "+", or "%20". | Jan 9, 2001 | 5.0 | 23 | NO | YES |
CVE-2014-8422HIGH The web-based management (WBM) interface in Unify (former Siemens) OpenStage SIP and OpenScape Desk Phone IP V3 devices before R3.32.0 generates session cookies with insufficient e | Apr 12, 2018 | 8.1 | 21 | NO | NO |
CVE-2014-8421HIGH Unify (former Siemens) OpenStage SIP and OpenScape Desk Phone IP V3 devices before R3.32.0 allow remote attackers to gain super-user privileges by leveraging SSH access and incorre | Apr 12, 2018 | 7.5 | 20 | NO | NO |
Signals from CVEs in this vendor scope (15 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Unify.
Media articles that mention a CVE ID that affects a product developed by Unify — matched by CVE ID, not by vendor name.