PT-2019-16062 · Alcatel Lucent · Alcatel-Lucent Omnivista 4760+1

0X1911

·

Publicado

2019-12-27

·

Atualizado

2020-01-07

·

CVE-2019-20047

CVSS v3.1

7.5

Alta

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Alcatel-Lucent OmniVista 4760 versions prior to 4.1.2 Alcatel-Lucent OmniVista 8770 versions prior to 4.1.2
Description An issue was discovered that allows a remote unauthenticated attacker to retrieve the content of its own session files due to an incorrect web server configuration. Each session file contains administrative LDAP credentials encoded in a reversible format. Sessions are stored in /sessions/sess .
Recommendations For Alcatel-Lucent OmniVista 4760 versions prior to 4.1.2, update to version 4.1.2 or later. For Alcatel-Lucent OmniVista 8770 versions prior to 4.1.2, update to version 4.1.2 or later.

Exploit

Correção

Insufficiently Protected Credentials

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2019-20047

Produtos afetados

Alcatel-Lucent Omnivista 4760
Alcatel-Lucent Omnivista 8770