Vulnerabilities > Atos > Openstage 15 G Firmware

DATE CVE VULNERABILITY TITLE RISK
2020-01-09 CVE-2014-2651 Improper Authentication vulnerability in Atos products
Unify OpenStage/OpenScape Desk Phone IP SIP before V3 R3.11.0 has an authentication bypass in the default mode of the Workpoint Interface
network
low complexity
atos CWE-287
critical
9.8
2020-01-09 CVE-2014-2650 OS Command Injection vulnerability in Atos products
Unify OpenStage / OpenScape Desk Phone IP before V3 R3.11.0 SIP has an OS command injection vulnerability in the web based management interface
network
low complexity
atos CWE-78
critical
9.8