CVE-2023-40265

An issue was discovered in Atos Unify OpenScape Xpressions WebAssistant V7 before V7R1 FR5 HF42 P911. It allows authenticated remote code execution via file upload.
References
Configurations

Configuration 1 (hide)

cpe:2.3:a:mitel:unify_openscape_xpressions_webassistant:*:*:*:*:*:*:*:*

History

15 Feb 2024, 16:00

Type Values Removed Values Added
CWE CWE-434
References () https://networks.unify.com/security/advisories/OBSO-2305-03.pdf - () https://networks.unify.com/security/advisories/OBSO-2305-03.pdf - Vendor Advisory
Summary
  • (es) Se descubrió un problema en Atos Unify OpenScape Xpressions WebAssistant V7 anterior a V7R1 FR5 HF42 P911. Permite la ejecución remota de código autenticado mediante la carga de archivos.
First Time Mitel
Mitel unify Openscape Xpressions Webassistant
CPE cpe:2.3:a:mitel:unify_openscape_xpressions_webassistant:*:*:*:*:*:*:*:*
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 8.8

08 Feb 2024, 22:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-02-08 22:15

Updated : 2024-02-15 16:00


NVD link : CVE-2023-40265

Mitre link : CVE-2023-40265

CVE.ORG link : CVE-2023-40265


JSON object : View

Products Affected

mitel

  • unify_openscape_xpressions_webassistant
CWE
CWE-434

Unrestricted Upload of File with Dangerous Type