PT-2016-7824 · Alcatel Lucent · Alcatel-Lucent Omnivista
Malerisch
·
Published
2016-12-03
·
Updated
2017-09-03
·
CVE-2016-9796
CVSS v2.0
10
Critical
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Alcatel-Lucent OmniVista versions 2.0 through 3.0
Description
The issue allows an attacker to bypass authentication and invoke certain methods, including
AddJobSet, AddJob, and ExecuteNow, which can be used to run arbitrary commands on the server with the privilege of NT AUTHORITYSYSTEM. This can be achieved by querying different ORBs interfaces using the GIOP protocol on TCP port 30024.Recommendations
For Alcatel-Lucent OmniVista versions 2.0 through 3.0, apply proper firewall rules to prevent unauthorized clients from connecting to the OmniVista server, as per the product security deployment technical guidelines.
Exploit
Fix
Improper Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Alcatel-Lucent Omnivista