CVE-2023-30638

HIGH

Atos Unify Openscape Bcf < 10r10.7.0 - Command Injection

Title source: rule
STIX 2.1

Description

Atos Unify OpenScape SBC 10 before 10R3.1.3, OpenScape Branch 10 before 10R3.1.2, and OpenScape BCF 10 before 10R10.7.0 allow remote authenticated admins to inject commands.

Scores

CVSS v3 7.2
EPSS 0.0096
EPSS Percentile 56.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-77 CWE-94
Status published
Products (3)
atos/unify_openscape_bcf 10 - 10r10.7.0
atos/unify_openscape_branch 10 - 10r3.1.2
atos/unify_openscape_session_border_controller 10 - 10r3.1.3
Published Apr 14, 2023
Tracked Since Feb 18, 2026