CVE-2007-3010
קריטית 9.8 מנוצלת בשטח (KEV)
ניצול פעיל מאומת — קטלוג CISA KEV
- שם
- Alcatel OmniPCX Enterprise Remote Code Execution Vulnerability
- נוסף לקטלוג
- יעד טיפול (פדרלי)
- פעולה נדרשת
- Apply updates per vendor instructions.
תיאור (מקור, אנגלית)
masterCGI in the Unified Maintenance Tool in Alcatel OmniPCX Enterprise Communication Server R7.1 and earlier allows remote attackers to execute arbitrary commands via shell metacharacters in the user parameter during a ping action.
מדדים
- CVSS 3.1
-
9.8 (CRITICAL)
מקור הציון: NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H - EPSS — סבירות ניצול
- 98% (אחוזון 100) נכון ל-24/7/2026
- CWE
- CWE-77
מוצרים מושפעים
al-enterprise: omnipcx enterprise communication server
קישורים
- http://secunia.com/advisories/26853 Broken LinkVendor Advisory
- http://secunia.com/advisories/26853 Broken LinkVendor Advisory
- http://marc.info/?l=full-disclosure&m=119002152126755&w=2 ExploitMailing List
- http://marc.info/?l=full-disclosure&m=119002152126755&w=2 ExploitMailing List
- http://osvdb.org/40521 Broken Link
- http://www.redteam-pentesting.de/advisories/rt-sa-2007-001.php Broken Link
- http://www.securityfocus.com/archive/1/479699/100/0/threaded Broken LinkThird Party AdvisoryVDB Entry
- http://www.securityfocus.com/bid/25694 Broken LinkThird Party AdvisoryVDB Entry
- http://www.vupen.com/english/advisories/2007/3185 Broken Link
- http://www1.alcatel-lucent.com/psirt/statements/2007002/OXEUMT.htm Broken Link