Permissions, Privileges, and Access Controls in Unify OpenScape 4000 and Unify OpenScape 4000 Manager - CVE-2025-23093
Published: January 24, 2025
Vulnerability identifier: #VU103279
CSH Severity: Low
CVSS v4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2025-23093
CWE-ID: CWE-264
Exploitation vector: Local access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a local user to escalate privileges on the system.
The vulnerability exists due to the execution of a resource with unnecessary privileges in the Platform component, which leads to security restrictions bypass and privilege escalation.
Affected software
Unify OpenScape 4000
Unify OpenScape 4000 Manager
Unify OpenScape 4000 Manager
How to mitigate CVE-2025-23093
Install updates from vendor's website.
Unify OpenScape 4000 - addressed in versions 10 R1.42.7, 10 R1.54.2, 11 R0.22.2
Unify OpenScape 4000 Manager - addressed in versions 10 R1.42.7, 10 R1.54.2, 11 R0.22.2
Unify OpenScape 4000 Manager - addressed in versions 10 R1.42.7, 10 R1.54.2, 11 R0.22.2