PT-2019-16062 · Alcatel Lucent · Alcatel-Lucent Omnivista 4760+1

0X1911

·

Published

2019-12-27

·

Updated

2020-01-07

·

CVE-2019-20047

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Alcatel-Lucent OmniVista 4760 versions prior to 4.1.2 Alcatel-Lucent OmniVista 8770 versions prior to 4.1.2
Description An issue was discovered that allows a remote unauthenticated attacker to retrieve the content of its own session files due to an incorrect web server configuration. Each session file contains administrative LDAP credentials encoded in a reversible format. Sessions are stored in /sessions/sess .
Recommendations For Alcatel-Lucent OmniVista 4760 versions prior to 4.1.2, update to version 4.1.2 or later. For Alcatel-Lucent OmniVista 8770 versions prior to 4.1.2, update to version 4.1.2 or later.

Exploit

Fix

Insufficiently Protected Credentials

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2019-20047

Affected Products

Alcatel-Lucent Omnivista 4760
Alcatel-Lucent Omnivista 8770