CVE-2023-40265

HIGH

Mitel Unify Openscape Xpressions Weba... - Unrestricted File Upload

Title source: rule
STIX 2.1

Description

An issue was discovered in Atos Unify OpenScape Xpressions WebAssistant V7 before V7R1 FR5 HF42 P911. It allows authenticated remote code execution via file upload.

References (1)

Core 1

Scores

CVSS v3 8.8
EPSS 0.0138
EPSS Percentile 80.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-434
Status published
Products (1)
mitel/unify_openscape_xpressions_webassistant 7.0 - 7r1_fr5_hf42_p911
Published Feb 08, 2024
Tracked Since Feb 18, 2026