Executive brief
The masterCGI component in the Unified Maintenance Tool of Alcatel OmniPCX Enterprise Communication Server allows remote attackers to execute arbitrary commands. The vulnerability is exploited via shell metacharacters in the user parameter during a ping action.
Affected products
- Alcatel-Lucent OmniPCX Enterprise Communication Server R7.1 and earlier
Timeline
- 2007-09-17: disclosed: Initial public disclosure via Full-Disclosure mailing list and RedTeam Pentesting advisory.
- 2022-04-15: kev added: Added to CISA's Known Exploited Vulnerabilities (KEV) Catalog.