Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Unify

First CVE: Jun 8, 2000Active for: 26 yearsTotal CVEs: 15
41.1
VTI Score
High

Unify develops telecommunications and unified communications infrastructure products, including IP desk phones, call servers, and middleware platforms such as the OpenStage and OpenScape lines, which occupy critical roles in enterprise communications networks. Vulnerabilities affecting the vendor skew toward serious outcomes and frequently acquire public exploit code; the exposure recurs across its product portfolio through weakness classes centered on path traversal, improper input validation, and exposure of sensitive information that are characteristic of server and middleware software exposed to untrusted network input. Current exploitation activity and exposure counts are shown alongside this summary.

FAUCET AI Generated
15
Total CVEs
More Total CVEs than 94% of tracked vendors
0.1
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 1% of tracked vendors
7.3
Avg CVSS Score
Higher Avg CVSS Score than 54% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Unify over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jun 8, 2000
26 years ago
Most Recent CVE
Feb 8, 2024
897 days ago

Products(28 total)

Top CVEs

Signals from CVEs in this vendor scope (15 CVEs).

15 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2014-2652CRITICAL
SQL injection vulnerability in OpenScape Deployment Service (DLS) before 6.x and 7.x before R1.11.3 allows remote attackers to execute arbitrary SQL commands via unspecified vector
Mar 19, 20189.831NONO
CVE-2023-36619CRITICAL
Atos Unify OpenScape Session Border Controller through V10 R3.01.03 allows execution of administrative scripts by unauthenticated users.
Oct 4, 20239.827NONO
CVE-2000-1024HIGH
eWave ServletExec 3.0C and earlier does not restrict access to the UploadServlet Java/JSP servlet, which allows remote attackers to upload files and execute arbitrary commands.
Dec 11, 200010.026NONO
CVE-2023-36618HIGH
Atos Unify OpenScape Session Border Controller through V10 R3.01.03 allows execution of OS commands as root user by low-privileged authenticated users.
Oct 4, 20238.825NONO
CVE-2000-1025MEDIUM
eWave ServletExec JSP/Java servlet engine, versions 3.0C and earlier, allows remote attackers to cause a denial of service via a URL that contains the "/servlet/" string, which inv
Dec 11, 20005.025NOYES
CVE-2023-40263HIGH
An issue was discovered in Atos Unify OpenScape Voice Trace Manager V8 before V8 R0.9.11. It allows authenticated command injection via ftp.
Feb 8, 20248.824NONO
CVE-2023-48166HIGH
A directory traversal vulnerability in the SOAP Server integrated in Atos Unify OpenScape Voice V10 before V10R3.26.1 allows a remote attacker to view the contents of arbitrary fil
Jan 12, 20247.523NONO
CVE-2000-1114MEDIUM
Unify ServletExec AS v3.0C allows remote attackers to read source code for JSP pages via an HTTP request that ends with characters such as ".", or "+", or "%20".
Jan 9, 20015.023NOYES
CVE-2014-8422HIGH
The web-based management (WBM) interface in Unify (former Siemens) OpenStage SIP and OpenScape Desk Phone IP V3 devices before R3.32.0 generates session cookies with insufficient e
Apr 12, 20188.121NONO
CVE-2014-8421HIGH
Unify (former Siemens) OpenStage SIP and OpenScape Desk Phone IP V3 devices before R3.32.0 allow remote attackers to gain super-user privileges by leveraging SSH access and incorre
Apr 12, 20187.520NONO
View all 15 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products15 CVEs
40%
47%
13%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network12 (80.0%)
Unknown3 (20.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low9 (60.0%)
High3 (20.0%)
Unknown3 (20.0%)
User Interaction
None11 (73.3%)
Unknown3 (20.0%)
Required1 (6.7%)
Privileges Required
Low4 (26.7%)
High1 (6.7%)
None7 (46.7%)
Unknown3 (20.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (15 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
2 CVEs
13.3% of CVEs· 76th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Unify.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Unify — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Unify's Products

View all 2 CNAs →

Top CWEs