CVE-2014-2650

Unify OpenStage / OpenScape Desk Phone IP before V3 R3.11.0 SIP has an OS command injection vulnerability in the web based management interface
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:atos:openstage_80_firmware:v3:r3.11.0:*:*:*:*:*:*
cpe:2.3:h:atos:openstage_80:-:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:o:atos:openstage_80_g_firmware:v3:r3.11.0:*:*:*:*:*:*
cpe:2.3:h:atos:openstage_80_g:-:*:*:*:*:*:*:*

Configuration 3 (hide)

AND
cpe:2.3:o:atos:openstage_60_g_firmware:v3:r3.11.0:*:*:*:*:*:*
cpe:2.3:h:atos:openstage_60_g:-:*:*:*:*:*:*:*

Configuration 4 (hide)

AND
cpe:2.3:o:atos:openstage_60_firmware:v3:r3.11.0:*:*:*:*:*:*
cpe:2.3:h:atos:openstage_60:-:*:*:*:*:*:*:*

Configuration 5 (hide)

AND
cpe:2.3:o:atos:openstage_40_firmware:v3:r3.11.0:*:*:*:*:*:*
cpe:2.3:h:atos:openstage_40:-:*:*:*:*:*:*:*

Configuration 6 (hide)

AND
cpe:2.3:o:atos:openstage_40_g_firmware:v3:r3.11.0:*:*:*:*:*:*
cpe:2.3:h:atos:openstage_40_g:-:*:*:*:*:*:*:*

Configuration 7 (hide)

AND
cpe:2.3:o:atos:openstage_20_e_firmware:v3:r3.11.0:*:*:*:*:*:*
cpe:2.3:h:atos:openstage_20_e:-:*:*:*:*:*:*:*

Configuration 8 (hide)

AND
cpe:2.3:o:atos:openstage_20_firmware:v3:r3.11.0:*:*:*:*:*:*
cpe:2.3:h:atos:openstage_20:-:*:*:*:*:*:*:*

Configuration 9 (hide)

AND
cpe:2.3:o:atos:openstage_20_g_firmware:v3:r3.11.0:*:*:*:*:*:*
cpe:2.3:h:atos:openstage_20_g:-:*:*:*:*:*:*:*

Configuration 10 (hide)

AND
cpe:2.3:o:atos:openstage_15_firmware:v3:r3.11.0:*:*:*:*:*:*
cpe:2.3:h:atos:openstage_15:-:*:*:*:*:*:*:*

Configuration 11 (hide)

AND
cpe:2.3:o:atos:openstage_15_g_firmware:v3:r3.11.0:*:*:*:*:*:*
cpe:2.3:h:atos:openstage_15_g:-:*:*:*:*:*:*:*

Configuration 12 (hide)

AND
cpe:2.3:o:atos:openstage_5_firmware:v3:r3.11.0:*:*:*:*:*:*
cpe:2.3:h:atos:openstage_5:-:*:*:*:*:*:*:*

Configuration 13 (hide)

AND
cpe:2.3:o:atos:openscape_desk_phone_ip_35g_firmware:v3:r3.11.0:*:*:*:*:*:*
cpe:2.3:h:atos:openscape_desk_phone_ip_35g:-:*:*:*:*:*:*:*

Configuration 14 (hide)

AND
cpe:2.3:o:atos:openscape_desk_phone_ip_35g_eco_firmware:v3:r3.11.0:*:*:*:*:*:*
cpe:2.3:h:atos:openscape_desk_phone_ip_35g_eco:-:*:*:*:*:*:*:*

Configuration 15 (hide)

AND
cpe:2.3:o:atos:openscape_desk_phone_ip_55g_firmware:v3:r3.11.0:*:*:*:*:*:*
cpe:2.3:h:atos:openscape_desk_phone_ip_55g:-:*:*:*:*:*:*:*

History

No history.

Information

Published : 2020-01-09 13:15

Updated : 2023-12-10 13:13


NVD link : CVE-2014-2650

Mitre link : CVE-2014-2650

CVE.ORG link : CVE-2014-2650


JSON object : View

Products Affected

atos

  • openscape_desk_phone_ip_55g
  • openstage_80_g_firmware
  • openstage_15_g
  • openstage_15_g_firmware
  • openstage_5
  • openstage_40
  • openstage_20_firmware
  • openstage_80
  • openscape_desk_phone_ip_35g
  • openstage_20
  • openstage_80_g
  • openstage_80_firmware
  • openstage_60
  • openstage_60_g
  • openstage_15
  • openscape_desk_phone_ip_35g_eco
  • openstage_20_g
  • openstage_40_g_firmware
  • openstage_40_g
  • openstage_5_firmware
  • openscape_desk_phone_ip_55g_firmware
  • openscape_desk_phone_ip_35g_firmware
  • openstage_20_g_firmware
  • openstage_60_firmware
  • openstage_15_firmware
  • openstage_20_e
  • openscape_desk_phone_ip_35g_eco_firmware
  • openstage_60_g_firmware
  • openstage_40_firmware
  • openstage_20_e_firmware
CWE
CWE-78

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')