QID 731283

Date Published: 2024-03-27

QID 731283: Alcatel-Lucent OmniPCX Enterprise Communication Server Remote Code Execution (RCE) Vulnerability

Alcatel OmniPCX Enterprise Communication Server is a voice, video and wireless call processing solution that offers broad scalability ranging from 10 to 100,000 users spread across multiple geographical sites.

CVE-2007-3010: Alcatel OmniPCX Enterprise Communication Server R7.1 and earlier is vulnerable to arbitrary command execution vulnerability.

Affected Versions:
Alcatel OmniPCX Enterprise Communication Server R7.1 and earlier

QID Detection Logic:
This QID sends a malicious GET request to endpoint "/cgi-bin/masterCGI" and executes "id" command.

Successful exploitation of this vulnerability may allow an unauthenticated attacker to execute arbitrary command on the target system.

  • CVSS V3 rated as Critical - 9.8 severity.
  • CVSS V2 rated as Critical - 10 severity.
  • Solution
    Customer are advised to update to latest versions of Alcatel-Lucent OmniPCX Enterprise Communication Server. For further information, please contact vendor Alcatel-Lucent for updates pertaining to this vulnerability.
    Vendor References

    CVEs related to QID 731283

    Software Advisories
    Advisory ID Software Component Link
    OmniPCX Enterprise Communication Server URL Logo www.al-enterprise.com/en/products/platforms/omnipcx-enterprise-communication-server