Title: Path Traversal vulnerability in Atos Unify OpenScape Voice
CVE ID: CVE-2023-48166
CVSSv3 Base Score: 7.4 (AV:A/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N)
Vendor: Unify
Products: OpenScape Voice
Advisory Release Date: 12-01-2024
Advisory URL: https://labs.integrity.pt/advisories/cve-2023-48166
Credits: Discovery by João Libório <joao.liborio[at]devoteam.com>
The SOAP Server integrated in Atos Unify OpenScape Voice is vulnerable to a path traversal that can be used to view the contents of arbritrary files in the local file system. This can allow an unauthenticated attacker to obtain information from sensitive files and compromise the underlying system.
© 2024 INTEGRITY S.A. All rights reserved. | Cookie Policy