CVE-2023-40265

HIGH

Unify OpenScape Xpressions WebAssistant 7.0-7r1_fr5_hf42_p911 - Authenticated Remote Code Execution via File Upload

Title source: llm
STIX 2.1

Description

An issue was discovered in Atos Unify OpenScape Xpressions WebAssistant V7 before V7R1 FR5 HF42 P911. It allows authenticated remote code execution via file upload.

References (1)

Core 1

Scores

CVSS v3 8.8
EPSS 0.0092
EPSS Percentile 55.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-434
Status published
Products (1)
mitel/unify_openscape_xpressions_webassistant 7.0 - 7r1_fr5_hf42_p911
Published Feb 08, 2024
Tracked Since Feb 18, 2026