CVE-2016-9796
Summary
| CVE | CVE-2016-9796 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2016-12-03 06:59:00 UTC |
| Updated | 2017-09-03 01:29:00 UTC |
| Description | Alcatel-Lucent OmniVista 8770 2.0 through 3.0 exposes different ORBs interfaces, which can be queried using the GIOP protocol on TCP port 30024. An attacker can bypass authentication, and OmniVista invokes methods (AddJobSet, AddJob, and ExecuteNow) that can be used to run arbitrary commands on the server, with the privilege of NT AUTHORITY\SYSTEM on the server. NOTE: The discoverer states "The vendor position is to refer to the technical guidelines of the product security deployment to mitigate this issue, which means applying proper firewall rules to prevent unauthorised clients to connect to the OmniVista server." |
Risk And Classification
Problem Types: CWE-287 | CWE-264
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Alcatel-lucent | Omnivista 8770 Network Management System | 2.0 | All | All | All |
| Application | Alcatel-lucent | Omnivista 8770 Network Management System | 2.6 | All | All | All |
| Application | Alcatel-lucent | Omnivista 8770 Network Management System | 3.0 | All | All | All |
| Application | Alcatel-lucent | Omnivista 8770 Network Management System | 2.0 | All | All | All |
| Application | Alcatel-lucent | Omnivista 8770 Network Management System | 2.6 | All | All | All |
| Application | Alcatel-lucent | Omnivista 8770 Network Management System | 3.0 | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Alcatel Lucent Omnivista 8770 Unauthenticated Remote Code Execution - YouTube | MISC | www.youtube.com | Exploit |
| Alcatel-Lucent OmniVista 8770 CVE-2016-9796 Remote Code Execution Vulnerability | BID | www.securityfocus.com | |
| Alcatel Lucent Omnivista 8770 - Remote Code Execution - Windows remote Exploit | EXPLOIT-DB | www.exploit-db.com | |
| malerisch.net: Alcatel Lucent Omnivista or: How I learned GIOP and gained Unauthenticated Remote Code Execution (CVE-2016-9796) | MISC | blog.malerisch.net | Exploit, Third Party Advisory |
| GitHub - malerisch/omnivista-8770-unauth-rce: Omnivista 8770 Unauthenticated Remote Code Execution - PoC | MISC | github.com | Third Party Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.