CVE-2022-46404

CRITICAL

Atos Unify OpenScape <8.22.18-10.28.13-10.R1.34.4 - Command Injection

Title source: llm
STIX 2.1

Description

A command injection vulnerability has been identified in Atos Unify OpenScape 4000 Assistant and Unify OpenScape 4000 Manager (8 before R2.22.18, 10 before 0.28.13, and 10 R1 before R1.34.4) that may allow an unauthenticated attacker to upload arbitrary files and achieve administrative access to the system.

Scores

CVSS v3 9.8
EPSS 0.0181
EPSS Percentile 75.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-77
Status published
Products (4)
atos/unify_openscape_4000_assistant 8
atos/unify_openscape_4000_assistant 10
atos/unify_openscape_4000_manager 8
atos/unify_openscape_4000_manager 10
Published Dec 13, 2022
Tracked Since Feb 18, 2026