PT-2016-7824 · Alcatel Lucent · Alcatel-Lucent Omnivista

Malerisch

·

Published

2016-12-03

·

Updated

2017-09-03

·

CVE-2016-9796

CVSS v2.0

10

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Alcatel-Lucent OmniVista versions 2.0 through 3.0
Description The issue allows an attacker to bypass authentication and invoke certain methods, including AddJobSet, AddJob, and ExecuteNow, which can be used to run arbitrary commands on the server with the privilege of NT AUTHORITYSYSTEM. This can be achieved by querying different ORBs interfaces using the GIOP protocol on TCP port 30024.
Recommendations For Alcatel-Lucent OmniVista versions 2.0 through 3.0, apply proper firewall rules to prevent unauthorized clients from connecting to the OmniVista server, as per the product security deployment technical guidelines.

Exploit

Fix

Improper Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2016-9796

Affected Products

Alcatel-Lucent Omnivista