Americas
Oceania
Advisory ID: OBSO-2407-01
Publish Date: 2024-07-10
Last Updated: 2024-07-10
Revision: 1.0
Product statements are related only to supported product versions. Products which have reached End of Support (M44) status are not considered.
The following products utilize the vulnerable PHP scripting engine:
Product Name | Product Version | Available Solution(s) |
---|---|---|
Unify OpenScape Voice Trace Manager | V8.R0.9.13 and earlier | Update to V8.R0.9.14 or later |
Unify OpenScape Deployment Service V10 (see Note 1)
Note 1:
OpenScape Deployment Service is not directly impacted as it does not deliver PHP. DLS delivers a PHP script (dls_directory_reader.php) that the admin can use to integrate DLS into an existing Apache server. Customers that use the PHP script should check their configuration and update their PHP stack to a fixed version.
CVSS3.1 Base score: 9.8 (Critical)
AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Customers with affected product versions are advised to update the systems with the available fixes.
- Operate OpenScape Voice Trace Manager in a secured network protected by a firewall
- Do not publicly expose OpenScape Voice Trace Manager web interface
- Restrict access web interface by restricting access to known ip networks/host ip addresses that require access
- Disable remote access to web interface and enable access through change management procedures when required
https://cve.mitre.org/cgi-bin/cvename.cgi?name=2024-4577
Version | Date | Description |
---|---|---|
1.0 | 10.07.2024 | Initial release |
Advisory: OBSO-2407-01, status: general release
Security Advisories are released as part of Mitel Unify's Vulnerability Intelligence Process. For more information see https://www.mitel.com/support/security-advisories.
Contact and Disclaimer
Mitel Product Security Office
[email protected]
© Unify Software and Solutions GmbH & Co. KG 2024
Otto-Hahn-Ring 6
D-81739 München
www.mitel.com
The information provided in this document contains merely general descriptions or characteristics of performance which in case of actual use do not always apply as described or which may change as a result of further development of the products. An obligation to provide the respective characteristics shall only exist if expressly agreed in the terms of contract. Availability and technical specifications are subject to change without notice.
Unify, OpenScape, OpenStage and HiPath are registered trademarks of Unify Software and Solutions GmbH & Co. KG.
All other company, brand, product, and service names are trademarks or registered trademarks of their respective holders