CVE-2008-4383
Stack-based buffer overflow in the Agranet-Emweb embedded management web server in Alcatel OmniSwitch OS7000, OS6600, OS6800, OS6850, and OS9000 Series devices with AoS 5.1 before 5.1.6.463.R02, 5.4 before 5.4.1.429.R01, 6.1.3 before 6.1.3.965.R01,…
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (8.21%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Stack-based buffer overflow in the Agranet-Emweb embedded management web server in Alcatel OmniSwitch OS7000, OS6600, OS6800, OS6850, and OS9000 Series devices with AoS 5.1 before 5.1.6.463.R02, 5.4 before 5.4.1.429.R01, 6.1.3 before 6.1.3.965.R01, 6.1.5 before 6.1.5.595.R01, and 6.3 before 6.3.1.966.R01 allows remote attackers to execute arbitrary code via a long Session cookie.
- CVSS 2.0
- 10.0 HIGHAV:N/AC:L/Au:N/C:C/I:C/A:C
- EPSS
- 8.21% probability · 95th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-119
- Affected
- alcatel/aos
- Source
- cret@cert.org
References
- http://secunia.com/advisories/31435Third Party Advisory
- http://securityreason.com/securityalert/4347Third Party Advisory
- http://www.layereddefense.com/alcatel12aug.htmlBroken Link
- http://www.securityfocus.com/archive/1/495343/100/0/threadedThird Party Advisory, VDB Entry
- http://www.securityfocus.com/bid/30652Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id?1020657Third Party Advisory, VDB Entry
- http://www.vupen.com/english/advisories/2008/2346Third Party Advisory
- http://www1.alcatel-lucent.com/psirt/statements/2008002/OmniSwitch.htmVendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/44400Third Party Advisory, VDB Entry
- http://secunia.com/advisories/31435Third Party Advisory
- http://securityreason.com/securityalert/4347Third Party Advisory
- http://www.layereddefense.com/alcatel12aug.htmlBroken Link
- http://www.securityfocus.com/archive/1/495343/100/0/threadedThird Party Advisory, VDB Entry
- http://www.securityfocus.com/bid/30652Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id?1020657Third Party Advisory, VDB Entry
- http://www.vupen.com/english/advisories/2008/2346Third Party Advisory
- http://www1.alcatel-lucent.com/psirt/statements/2008002/OmniSwitch.htmVendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/44400Third Party Advisory, VDB Entry
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.