CVE-2014-2650: Atos Openscape Desk Phone IP 35g Eco Firmware

Critical severity, CVSS 9.8. EPSS: 2.6% chance of exploitation in the next 30 days.

Unify OpenStage / OpenScape Desk Phone IP before V3 R3.11.0 SIP has an OS command injection vulnerability in the web based management interface

Affected products

  • Atos Openscape Desk Phone IP 35g Eco Firmware: version v3 only
  • Atos Openscape Desk Phone IP 35g Firmware: version v3 only
  • Atos Openscape Desk Phone IP 55g Firmware: version v3 only
  • Atos Openstage 15 Firmware: version v3 only
  • Atos Openstage 15 G Firmware: version v3 only
  • Atos Openstage 20 E Firmware: version v3 only
  • Atos Openstage 20 Firmware: version v3 only
  • Atos Openstage 20 G Firmware: version v3 only
  • Atos Openstage 40 Firmware: version v3 only
  • Atos Openstage 40 G Firmware: version v3 only
  • Atos Openstage 5 Firmware: version v3 only
  • Atos Openstage 60 Firmware: version v3 only
  • Atos Openstage 60 G Firmware: version v3 only
  • Atos Openstage 80 Firmware: version v3 only
  • Atos Openstage 80 G Firmware: version v3 only

Published 2020-01-09. Last modified 2026-06-17.