CVE-2014-2651

Unify OpenStage/OpenScape Desk Phone IP SIP before V3 R3.11.0 has an authentication bypass in the default mode of the Workpoint Interface
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:atos:openstage_80_firmware:v3:r3.11.0:*:*:*:*:*:*
cpe:2.3:h:atos:openstage_80:-:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:o:atos:openstage_80_g_firmware:v3:r3.11.0:*:*:*:*:*:*
cpe:2.3:h:atos:openstage_80_g:-:*:*:*:*:*:*:*

Configuration 3 (hide)

AND
cpe:2.3:o:atos:openstage_60_g_firmware:v3:r3.11.0:*:*:*:*:*:*
cpe:2.3:h:atos:openstage_60_g:-:*:*:*:*:*:*:*

Configuration 4 (hide)

AND
cpe:2.3:o:atos:openstage_60_firmware:v3:r3.11.0:*:*:*:*:*:*
cpe:2.3:h:atos:openstage_60:-:*:*:*:*:*:*:*

Configuration 5 (hide)

AND
cpe:2.3:o:atos:openstage_40_firmware:v3:r3.11.0:*:*:*:*:*:*
cpe:2.3:h:atos:openstage_40:-:*:*:*:*:*:*:*

Configuration 6 (hide)

AND
cpe:2.3:o:atos:openstage_40_g_firmware:v3:r3.11.0:*:*:*:*:*:*
cpe:2.3:h:atos:openstage_40_g:-:*:*:*:*:*:*:*

Configuration 7 (hide)

AND
cpe:2.3:o:atos:openstage_20_e_firmware:v3:r3.11.0:*:*:*:*:*:*
cpe:2.3:h:atos:openstage_20_e:-:*:*:*:*:*:*:*

Configuration 8 (hide)

AND
cpe:2.3:o:atos:openstage_20_firmware:v3:r3.11.0:*:*:*:*:*:*
cpe:2.3:h:atos:openstage_20:-:*:*:*:*:*:*:*

Configuration 9 (hide)

AND
cpe:2.3:o:atos:openstage_20_g_firmware:v3:r3.11.0:*:*:*:*:*:*
cpe:2.3:h:atos:openstage_20_g:-:*:*:*:*:*:*:*

Configuration 10 (hide)

AND
cpe:2.3:o:atos:openstage_15_firmware:v3:r3.11.0:*:*:*:*:*:*
cpe:2.3:h:atos:openstage_15:-:*:*:*:*:*:*:*

Configuration 11 (hide)

AND
cpe:2.3:o:atos:openstage_15_g_firmware:v3:r3.11.0:*:*:*:*:*:*
cpe:2.3:h:atos:openstage_15_g:-:*:*:*:*:*:*:*

Configuration 12 (hide)

AND
cpe:2.3:o:atos:openscape_desk_phone_ip_35g_firmware:v3:r3.11.0:*:*:*:*:*:*
cpe:2.3:h:atos:openscape_desk_phone_ip_35g:-:*:*:*:*:*:*:*

Configuration 13 (hide)

AND
cpe:2.3:o:atos:openscape_desk_phone_ip_35g_eco_firmware:v3:r3.11.0:*:*:*:*:*:*
cpe:2.3:h:atos:openscape_desk_phone_ip_35g_eco:-:*:*:*:*:*:*:*

Configuration 14 (hide)

AND
cpe:2.3:o:atos:openscape_desk_phone_ip_55g_firmware:v3:r3.11.0:*:*:*:*:*:*
cpe:2.3:h:atos:openscape_desk_phone_ip_55g:-:*:*:*:*:*:*:*

History

21 Nov 2024, 02:06

Type Values Removed Values Added
References () http://assets.yourcircuit.com/Internet/web/Container%20Site/Misc/Footer-content/privacy-policy/security-advisories.aspx - Third Party Advisory () http://assets.yourcircuit.com/Internet/web/Container%20Site/Misc/Footer-content/privacy-policy/security-advisories.aspx - Third Party Advisory
References () https://networks.unify.com/security/advisories/OBSO-1403-02.pdf - Vendor Advisory () https://networks.unify.com/security/advisories/OBSO-1403-02.pdf - Vendor Advisory

Information

Published : 2020-01-09 13:15

Updated : 2024-11-21 02:06


NVD link : CVE-2014-2651

Mitre link : CVE-2014-2651

CVE.ORG link : CVE-2014-2651


JSON object : View

Products Affected

atos

  • openstage_20
  • openstage_15
  • openstage_40_g_firmware
  • openstage_60_firmware
  • openstage_80
  • openstage_15_g
  • openscape_desk_phone_ip_35g_eco
  • openstage_80_g
  • openstage_20_g_firmware
  • openstage_20_e
  • openscape_desk_phone_ip_35g
  • openstage_15_g_firmware
  • openstage_40
  • openstage_40_g
  • openstage_20_firmware
  • openstage_15_firmware
  • openscape_desk_phone_ip_35g_eco_firmware
  • openscape_desk_phone_ip_35g_firmware
  • openstage_60_g
  • openstage_20_e_firmware
  • openstage_60
  • openstage_80_firmware
  • openstage_20_g
  • openscape_desk_phone_ip_55g
  • openstage_80_g_firmware
  • openstage_60_g_firmware
  • openstage_40_firmware
  • openscape_desk_phone_ip_55g_firmware
CWE
CWE-287

Improper Authentication