#OpenScape
Jetzt sitze ich hier, registriere mich bei "Unify Phone for OpenScape" (was auch immer das heißen soll - es "vereinheitlicht OpenScape Business") und muss irgendwelche Rechte verwalten...

Inzwischen weiß ich wie es Mandanten geht, denen ich eine GmbH&Co KG andrehe...
October 16, 2024 at 8:36 AM
Ist es ein "Unify openScape Desk Phone"? 😂
January 7, 2025 at 9:59 AM
January 31, 2026 at 6:18 PM
OpenScape Desk? Benutze nur noch den Web Client, ich habe noch nicht herausgefunden, wie man das Blinken abschalten kann. 😩
October 24, 2025 at 6:48 AM
CVE-2025-23093 & CVE-2025-23094: Mitel OpenScape Users Urged to Update Now securityonline.info/cve-2025-230...
CVE-2025-23093 & CVE-2025-23094: Mitel OpenScape Users Urged to Update Now
Mitel's urgent security advisory warns of high-severity vulnerabilities affecting their OpenScape 4000 platforms. Learn about CVE-2025-23093 and CVE-2025-23094.
securityonline.info
January 28, 2025 at 3:57 AM
August 8, 2026 at 2:25 PM
January 3, 2026 at 8:53 AM
December 13, 2024 at 10:35 AM
🚨🆘

Dear FORRT members:

We're applying for the OSCARS to fund the OpenScape Atlas—a FAIR global map of Open Science infrastructures!

We need YOUR support to sign our community letter ✍️

🕐 Deadline: 16h CEST in 5 hours 🫣

To sign it, go to Slack where you find our application & letter of support!
May 14, 2025 at 8:49 AM
I get that. There's also FOSS alternates that can the same thing like openscape or 2009scape.

There's being part of the system and living it. Then there's adapting to the system. Yeah. Stuff shouldn't be expensive and inaccessible. But being in the system makes it hard not to be practical.
March 10, 2026 at 5:01 PM
Si vous suivez les vulnérabilités, sachez que le CERT-FR dispose d'un fil RSS avec toutes les annonces.

www.cert.ssi.gouv.fr/feed/
CERT-FRMultiples vulnérabilités dans les produits Stormshield (16 juillet 2024)Multiples vulnérabilités dans les produits Siemens (13 août 2024)Multiples vulnérabilités dans Xen (16 août 2024)Multiples vulnérabilités dans Mitel Unify OpenScape Business Application (16 août 2024)Vulnérabilité dans Grafana (16 août 2024)Multiples vulnérabilités dans Spring Framework (16 août 2024)Vulnérabilité dans Elastic APM Server (16 août 2024)Multiples vulnérabilités dans les produits Palo Alto Networks (16 août 2024)Multiples vulnérabilités dans les produits IBM (16 août 2024)Multiples vulnérabilités dans le noyau Linux de SUSE (16 août 2024)Multiples vulnérabilités dans le noyau Linux d'Ubuntu (16 août 2024)Multiples vulnérabilités dans le noyau Linux de Red Hat (16 août 2024)Bulletin d'actualité CERTFR-2024-ACT-037 (19 août 2024)Multiples vulnérabilités dans Moodle (19 août 2024)Vulnérabilité dans Microsoft Edge (19 août 2024)Vulnérabilité dans Microsoft Office (19 août 2024)Multiples vulnérabilités dans les produits F5 et Nginx (19 août 2024)Vulnérabilité dans Spring Security (20 août 2024)Multiples vulnérabilités dans Joomla! (21 août 2024)Vulnérabilité dans SPIP (21 août 2024)Multiples vulnérabilités dans les produits Atlassian (21 août 2024)Vulnérabilité dans Microsoft Azure (21 août 2024)Vulnérabilité dans MongoDB (21 août 2024)Multiples vulnérabilités dans Google Chrome (22 août 2024)Vulnérabilité dans Mitel MiContact Center Business (22 août 2024)Vulnérabilité dans les produits Cisco (22 août 2024)Multiples vulnérabilités dans GitLab (22 août 2024)Multiples vulnérabilités dans Dovecot (22 août 2024)Multiples vulnérabilités dans Microsoft Edge (23 août 2024)Vulnérabilité dans les produits Sonicwall (23 août 2024)Multiples vulnérabilités dans les produits VMware (23 août 2024)Vulnérabilité dans SolarWinds Web Help Desk (23 août 2024)Vulnérabilité dans Spring Boot (23 août 2024)Multiples vulnérabilités dans le noyau Linux d'Ubuntu (23 août 2024)Multiples vulnérabilités dans le noyau Linux de SUSE (23 août 2024)Multiples vulnérabilités dans le noyau Linux de Red Hat (23 août 2024)Multiples vulnérabilités dans le noyau Linux de Debian (23 août 2024)Multiples vulnérabilités dans IBM QRadar SIEM (23 août 2024)Bulletin d'actualité CERTFR-2024-ACT-038 (26 août 2024)Vulnérabilité dans Microsoft Edge (26 août 2024)
www.cert.ssi.gouv.fr
August 27, 2024 at 9:44 AM
Notícia da SecurityOnline

"CVE-2025-23093 & CVE-2025-23094: Usuários do Mitel OpenScape São Urgidos a Atualizar Agora" #bolhasec
CVE-2025-23093 & CVE-2025-23094: Mitel OpenScape Users Urged to Update Now
Mitel's urgent security advisory warns of high-severity vulnerabilities affecting their OpenScape 4000 platforms. Learn about CVE-2025-23093 and CVE-2025-23094.
securityonline.info
January 28, 2025 at 1:30 PM
Mitel OpenScape Flaw (CVE-2025-23092): High-Severity Path Traversal Allows Admin RCE
Mitel OpenScape Flaw (CVE-2025-23092): High-Severity Path Traversal Allows Admin RCE
A high-severity path traversal flaw (CVE-2025-23092) in Mitel OpenScape Accounting Management allows authenticated admins to upload malicious files for RCE. Update now!
securityonline.info
June 14, 2025 at 4:31 AM
Atos Unify OpenScape reports maximum severity critical vulnerability
Atos Unify OpenScape reports maximum severity critical vulnerability
Take action: This is a "LOCK DOWN AND PATCH IMMEDIATELY" advisory. Any publicly exposed SSH and management interface of OpenScape will be scanned automatically and compromised. Close SSH and management interfaces from any public internet access and patch ASAP. Learn More A critical security vulnerability, tracked as CVE-2023-6269 (CVSS3 score 10) - a maximum CVSS score, has been reported within Atos Unify's OpenScape suite, impacting the OpenScape SBC, Branch, and BCF products. Atos Unify OpenScape is a comprehensive suite of communication and collaboration tools developed by Atos Unify. It integrates various communication channels like voice, video, messaging, and conferencing into a unified platform. OpenScape offers advanced IP telephony, conferencing tools, contact center solutions, and mobility support. This flaw, identified as an argument injection issue, enables unauthorized individuals to circumvent the administrative web interfaces, potentially executing arbitrary code and gaining root access through SSH, thereby compromising the entire system. The vulnerability arises due to the administrative web interface's failure to properly sanitize login credentials before they are processed by a user management application , creating a gateway for unauthorized control and access. The products confirmed as vulnerable include several versions of Atos Unify OpenScape SBC, Branch, and BCF, specifically those preceding the latest updates. The versions at risk are: OpenScape SBC prior to V10 R3.4.0 OpenScape Branch prior to V10 R3.4.0 OpenScape BCF V10 before versions V10R10.12.00 and V10R11.05.02 For these affected versions, the respective updated versions are: OpenScape SBC V10 R3.4.0 or later OpenScape Branch V10 R3.4.0 or later OpenScape BCF V10R10.12.00 or later, and V10R11.05.02 Users of these systems are strongly advised to promptly update to the fixed versions to neutralize this threat. Moreover, several preventive measures have been recommended, such as disabling SSH access for low-privileged accounts, ensuring the root account is inaccessible via SSH, limiting external SSH access, and refraining from publicly exposing the administration interface of the affected systems.
beyondmachines.net
December 6, 2023 at 8:23 AM
Atos Unify Vulnerabilities Let Attacker Execute Remote Code
Atos Unify Vulnerabilities Let Attacker Execute Remote Code
Two vulnerabilities have been identified on three Atos Unify OpenScape products, SBC, Branch, and BCF, which are associated with Missing authentication.
cybersecuritynews.com
September 21, 2023 at 2:58 PM
Multiples vulnérabilités dans Mitel Unify OpenScape Business Application (16 août 2024)
Multiples vulnérabilités dans Mitel Unify OpenScape Business Application - CERT-FR
www.cert.ssi.gouv.fr
August 16, 2024 at 3:22 PM
CVE-2025-48026 - Mitel OpenScape Xpressions WebApl Path Traversal Vulnerability
CVE ID : CVE-2025-48026

Published : June 23, 2025, 8:15 p.m. | 3 hours, 50 minutes ago

Description : A vulnerability in the WebApl component of Mitel OpenScape Xpressions through V7R1 FR5 HF4...
CVE-2025-48026 - Mitel OpenScape Xpressions WebApl Path Traversal Vulnerability
A vulnerability in the WebApl component of Mitel OpenScape Xpressions through V7R1 FR5 HF43 P913 could allow an unauthenticated attacker to conduct a path traversal attack due to insufficient input validation. A successful exploit could allow an attacker to read files from the underlying OS and obtain sensitive information.
cvefeed.io
June 24, 2025 at 12:15 AM
CVE-2025-23092 - Mitel OpenScape Accounting Path Traversal Vulnerability
CVE ID : CVE-2025-23092

Published : June 23, 2025, 9:15 p.m. | 2 hours, 50 minutes ago

Description : Mitel OpenScape Accounting Management through V5 R1.1.0 could allow an authenticated attacker wit...
CVE-2025-23092 - Mitel OpenScape Accounting Path Traversal Vulnerability
Mitel OpenScape Accounting Management through V5 R1.1.0 could allow an authenticated attacker with administrative privileges to conduct a path traversal attack due to insufficient sanitization of user input. A successful exploit could allow an attacker to upload arbitrary files and execute unauthorized commands.
cvefeed.io
June 24, 2025 at 12:13 AM
CVE-2025-23094 - Mitel OpenScape 4000 Command Injection Vulnerability
CVE ID : CVE-2025-23094

Published : Feb. 6, 2025, 9:15 p.m. | 1 hour, 30 minutes ago

Description : The Platform component of Mitel OpenScape 4000 and OpenScape 4000 Manager V11 R0.22.0 through V11 R0.2...
CVE-2025-23094 - Mitel OpenScape 4000 Command Injection Vulnerability
The Platform component of Mitel OpenScape 4000 and OpenScape 4000 Manager V11 R0.22.0 through V11 R0.22.1, V10 R1.54.0 through V10 R1.54.1, and V10 R1.42.6 and earlier could allow an unauthenticated attacker to conduct a command injection attack due to insufficient parameter sanitization. A successful exploit could allow an attacker to …
cvefeed.io
February 6, 2025 at 10:49 PM
CVE-2025-23093 - Mitel OpenScape 4000 Privilege Escalation Vulnerability
CVE ID : CVE-2025-23093

Published : Feb. 6, 2025, 8:15 p.m. | 2 hours, 30 minutes ago

Description : The Platform component of Mitel OpenScape 4000 and OpenScape 4000 Manager through V10 R1.54.1 and ...
CVE-2025-23093 - Mitel OpenScape 4000 Privilege Escalation Vulnerability
The Platform component of Mitel OpenScape 4000 and OpenScape 4000 Manager through V10 R1.54.1 and V11 through R0.22.1 could allow an authenticated attacker to conduct a privilege escalation attack due to the execution of a resource with unnecessary privileges. A successful exploit could allow an attacker to execute arbitrary commands …
cvefeed.io
February 6, 2025 at 10:49 PM
Argument injection leading to unauthenticated RCE and authentication bypass in Atos Unify OpenScape Session Border Controller (and Branch, BCF products)
Argument injection leading to unauthenticated RCE and authentication bypass in Atos Unify OpenScape Session Border Controller (and Branch, BCF products)
sec-consult.com
December 5, 2023 at 11:58 AM