Unify OpenStage / OpenScape Desk Phone IP before V3 R3.11.0 SIP has an OS command injection vulnerability in the web based management interface
| Software | From | Fixed in |
|---|---|---|
| atos / openstage_80_firmware | 3-r3.11.0 | 3-r3.11.0.x |
| atos / openstage_80_g_firmware | 3-r3.11.0 | 3-r3.11.0.x |
| atos / openstage_60_g_firmware | 3-r3.11.0 | 3-r3.11.0.x |
| atos / openstage_60_firmware | 3-r3.11.0 | 3-r3.11.0.x |
| atos / openstage_40_firmware | 3-r3.11.0 | 3-r3.11.0.x |
| atos / openstage_40_g_firmware | 3-r3.11.0 | 3-r3.11.0.x |
| atos / openstage_20_e_firmware | 3-r3.11.0 | 3-r3.11.0.x |
| atos / openstage_20_firmware | 3-r3.11.0 | 3-r3.11.0.x |
| atos / openstage_20_g_firmware | 3-r3.11.0 | 3-r3.11.0.x |
| atos / openstage_15_firmware | 3-r3.11.0 | 3-r3.11.0.x |
| atos / openstage_15_g_firmware | 3-r3.11.0 | 3-r3.11.0.x |
| atos / openstage_5_firmware | 3-r3.11.0 | 3-r3.11.0.x |
| atos / openscape_desk_phone_ip_35g_firmware | 3-r3.11.0 | 3-r3.11.0.x |
| atos / openscape_desk_phone_ip_35g_eco_firmware | 3-r3.11.0 | 3-r3.11.0.x |
| atos / openscape_desk_phone_ip_55g_firmware | 3-r3.11.0 | 3-r3.11.0.x |