SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityAnalyzed

CVE-2007-3010

Alcatel OmniPCX Enterprise Remote Code Execution Vulnerability

KEVCRITICAL 9.8EPSS 97.4%

Does this matter?

Known to be exploited in the wild (CISA KEV, CISA remediation deadline 6 May 2022). Treat as an emergency change: patch or isolate now, then hunt for prior compromise.

Description

masterCGI in the Unified Maintenance Tool in Alcatel OmniPCX Enterprise Communication Server R7.1 and earlier allows remote attackers to execute arbitrary commands via shell metacharacters in the user parameter during a ping action.

CVSS 3.1
9.8 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS
97.41% probability · 100th percentile
CISA KEV
Listed 15 April 2022 · due 6 May 2022
Weakness
CWE-77
Affected
al-enterprise/omnipcx enterprise communication server
Source
cve@mitre.org

CISA notes

Apply updates per vendor instructions. https://nvd.nist.gov/vuln/detail/CVE-2007-3010

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.