PT-2024-22767 · Alcatel Lucent · Alcatel-Lucent Ale Noe Deskphones+1

Moritz Abrell

·

Published

2024-05-07

·

Updated

2024-07-03

·

CVE-2024-29150

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Alcatel-Lucent ALE NOE deskphones versions 86x8 NOE-R300.1.40.12.4180 and earlier Alcatel-Lucent ALE SIP deskphones versions 86x8 SIP-R200.1.01.10.728 and earlier
Description An issue was discovered due to improper privilege management, allowing an authenticated attacker to create symlinks to sensitive and protected data in locations used for debugging files. The process of gathering debug logs is carried out with root privileges, granting the attacker accessibility to any file referenced in the symlink, which is then written to the debug archive.
Recommendations For Alcatel-Lucent ALE NOE deskphones versions 86x8 NOE-R300.1.40.12.4180 and earlier, consider restricting access to sensitive data until a patch is available. For Alcatel-Lucent ALE SIP deskphones versions 86x8 SIP-R200.1.01.10.728 and earlier, consider restricting access to sensitive data until a patch is available. As a temporary workaround, consider disabling the debugging file functionality until a patch is available.

Fix

Improper Privilege Management

Weakness Enumeration

Related Identifiers

CVE-2024-29150

Affected Products

Alcatel-Lucent Ale Noe Deskphones
Alcatel-Lucent Ale Sip Deskphones