Back to Database
Status published
Critical
CVE-2014-2651
Unify OpenStage/OpenScape Desk Phone IP SIP before V3 R3.11.0 has...
Vulnerability Description
Unify OpenStage/OpenScape Desk Phone IP SIP before V3 R3.11.0 has an authentication bypass in the default mode of the Workpoint Interface
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2014-2651
Credits & Attribution
No credits recorded in the NVD database.
References
More from atos
View All →CVE-2022-46404
A command injection vulnerability has been identified in Atos Unify...
Critical
9.8
CVE-2022-36444
An issue was discovered in Atos Unify OpenScape SBC 9...
High
8.6
CVE-2019-19866
Atos Unify OpenScape UC Web Client V9 before version V9...
High
7.5
CVE-2019-19865
Atos Unify OpenScape UC Application V9 before version V9 R4.31.0...
Medium
6.1
CVE-2014-2650
Unify OpenStage / OpenScape Desk Phone IP before V3 R3.11.0...
Critical
9.8
Affected Vendor
atos
View all reports →Affected Software
openstage 80 firmware, openstage 80 g firmware, openstage 60 g firmware, openstage 60 firmware, openstage 40 firmware, openstage 40 g firmware, openstage 20 e firmware, openstage 20 firmware, openstage 20 g firmware, openstage 15 firmware, openstage 15 g firmware, openscape desk phone ip 35g firmware, openscape desk phone ip 35g eco firmware, openscape desk phone ip 55g firmware
Vulnerable Versions:
v3
Timeline
Official Publish:
January 9th, 2020
Last Modified:
August 6th, 2024
Added to House:
July 19th, 2026
CVSS Vectors
V3:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.