PT-2016-7824 · Alcatel Lucent · Alcatel-Lucent Omnivista

Malerisch

·

Publicado

2016-12-03

·

Atualizado

2017-09-03

·

CVE-2016-9796

CVSS v2.0

10

Crítica

VetorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Alcatel-Lucent OmniVista versions 2.0 through 3.0
Description The issue allows an attacker to bypass authentication and invoke certain methods, including AddJobSet, AddJob, and ExecuteNow, which can be used to run arbitrary commands on the server with the privilege of NT AUTHORITYSYSTEM. This can be achieved by querying different ORBs interfaces using the GIOP protocol on TCP port 30024.
Recommendations For Alcatel-Lucent OmniVista versions 2.0 through 3.0, apply proper firewall rules to prevent unauthorized clients from connecting to the OmniVista server, as per the product security deployment technical guidelines.

Exploit

Correção

Improper Authentication

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2016-9796

Produtos afetados

Alcatel-Lucent Omnivista