Junglewise Threat Intelligence

CVE-2007-3010: Alcatel OmniPCX Enterprise Remote Code Execution Vulnerability

CVE-2007-3010 · Severity: critical · CVSS 9.8 · Exploited in the wild · Published 2022-04-15

Executive brief

The masterCGI component in the Unified Maintenance Tool of Alcatel OmniPCX Enterprise Communication Server allows remote attackers to execute arbitrary commands. The vulnerability is exploited via shell metacharacters in the user parameter during a ping action.

Affected products

  • Alcatel-Lucent OmniPCX Enterprise Communication Server R7.1 and earlier

Timeline

  • 2007-09-17: disclosed: Initial public disclosure via Full-Disclosure mailing list and RedTeam Pentesting advisory.
  • 2022-04-15: kev added: Added to CISA's Known Exploited Vulnerabilities (KEV) Catalog.