CVE-2014-2651: Atos Openscape Desk Phone IP 35g Eco Firmware

Critical severity, CVSS 9.8. EPSS: 1.7% chance of exploitation in the next 30 days.

Unify OpenStage/OpenScape Desk Phone IP SIP before V3 R3.11.0 has an authentication bypass in the default mode of the Workpoint Interface

Affected products

  • Atos Openscape Desk Phone IP 35g Eco Firmware: version v3 only
  • Atos Openscape Desk Phone IP 35g Firmware: version v3 only
  • Atos Openscape Desk Phone IP 55g Firmware: version v3 only
  • Atos Openstage 15 Firmware: version v3 only
  • Atos Openstage 15 G Firmware: version v3 only
  • Atos Openstage 20 E Firmware: version v3 only
  • Atos Openstage 20 Firmware: version v3 only
  • Atos Openstage 20 G Firmware: version v3 only
  • Atos Openstage 40 Firmware: version v3 only
  • Atos Openstage 40 G Firmware: version v3 only
  • Atos Openstage 60 Firmware: version v3 only
  • Atos Openstage 60 G Firmware: version v3 only
  • Atos Openstage 80 Firmware: version v3 only
  • Atos Openstage 80 G Firmware: version v3 only

Published 2020-01-09. Last modified 2026-06-17.