PT-2024-22767 · Alcatel Lucent · Alcatel-Lucent Ale Noe Deskphones+1
Moritz Abrell
·
Published
2024-05-07
·
Updated
2024-07-03
·
CVE-2024-29150
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Alcatel-Lucent ALE NOE deskphones versions 86x8 NOE-R300.1.40.12.4180 and earlier
Alcatel-Lucent ALE SIP deskphones versions 86x8 SIP-R200.1.01.10.728 and earlier
Description
An issue was discovered due to improper privilege management, allowing an authenticated attacker to create symlinks to sensitive and protected data in locations used for debugging files. The process of gathering debug logs is carried out with root privileges, granting the attacker accessibility to any file referenced in the symlink, which is then written to the debug archive.
Recommendations
For Alcatel-Lucent ALE NOE deskphones versions 86x8 NOE-R300.1.40.12.4180 and earlier, consider restricting access to sensitive data until a patch is available.
For Alcatel-Lucent ALE SIP deskphones versions 86x8 SIP-R200.1.01.10.728 and earlier, consider restricting access to sensitive data until a patch is available.
As a temporary workaround, consider disabling the debugging file functionality until a patch is available.
Fix
Improper Privilege Management
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Alcatel-Lucent Ale Noe Deskphones
Alcatel-Lucent Ale Sip Deskphones