Alcatel-Lucent records
27 published records for vendor alcatel-lucent.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 4
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')4
- CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer3
- CWE-352 Cross-Site Request Forgery (CSRF)2
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor2
- CWE-264 Permissions, Privileges, and Access Controls2
- CWE-367 Time-of-check Time-of-use (TOCTOU) Race Condition1
The weakness classes this vendor ships most often: where to look.
CWEAll records
27 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
43Plan | CVE-2016-9796Proof of concept | Alcatel-Lucent OmniVista 8770 2.0 through 3.0 exposes different ORBs interfaces, which can be queried using the GIOP protocol on TCP port 30alcatel-lucent · omnivista 8770 network management system · CWE-264 | Critical9.8 | — | 13.4% | Dec 3, 2016 |
43Plan | CVE-2008-1331Proof of concept | cgi-data/FastJSData.cgi in OmniPCX Office with Internet Access services OXO210 before 210/091.001, OXO600 before 610/014.001, and other versalcatel-lucent · omnipcx office · CWE-20 | Critical10.0 | — | 8.8% | Apr 2, 2008 |
42Plan | CVE-2008-4383No exploit | Stack-based buffer overflow in the Agranet-Emweb embedded management web server in Alcatel OmniSwitch OS7000, OS6600, OS6800, OS6850, and OSalcatel · aos · CWE-119 | Critical10.0 | — | 8.2% | Oct 3, 2008 |
41Plan | CVE-2002-1691No exploit | Alcatel OmniPCX 4400 installs known user accounts and passwords in the /etc/password file by default, which allows remote attackers to gain alcatel-lucent · omnipcx | Critical10.0 | — | 3.6% | Dec 31, 2002 |
41Plan | CVE-2007-1822No exploit | Alcatel-Lucent Lucent Technologies voice mail systems allow remote attackers to retrieve or remove messages, or reconfigure mailboxes, by spalcatel-lucent · voice mail system | Critical10.0 | — | 3.1% | Apr 2, 2007 |
35Monitor | CVE-2007-5361No exploit | The Communication Server in Alcatel-Lucent OmniPCX Enterprise 7.1 and earlier caches an IP address during a TFTP request from an IP Touch phalcatel-lucent · omnipcx | High8.5 | — | 2.4% | Nov 20, 2007 |
32Monitor | CVE-2007-0931No exploit | Heap-based buffer overflow in the management interfaces in (1) Aruba Mobility Controllers 200, 800, 2400, and 6000 and (2) Alcatel-Lucent Omalcatel-lucent · omniaccess wireless | High7.5 | — | 6.1% | Feb 14, 2007 |
31Monitor | CVE-2007-0932No exploit | The (1) Aruba Mobility Controllers 200, 600, 2400, and 6000 and (2) Alcatel-Lucent OmniAccess Wireless 43xx and 6000 do not properly implemealcatel-lucent · omniaccess wireless · CWE-264 | High7.5 | — | 2.3% | Feb 14, 2007 |
31Monitor | CVE-2015-6498No exploit | Alcatel-Lucent Home Device Manager before 4.1.10, 4.2.x before 4.2.2 allows remote attackers to spoof and make calls as target devices.alcatel-lucent · home device manager · CWE-254 | High7.5 | — | 2.2% | Aug 9, 2017 |
30Monitor | CVE-2007-2512No exploit | Alcatel-Lucent IP-Touch Telephone running OmniPCX Enterprise 7.0 and later enables the mini switch by default, which allows attackers to gaialcatel-lucent · omnipcx | High7.5 | — | 1.2% | Jun 7, 2007 |
30Monitor | CVE-2010-3279No exploit | The default configuration of the CCAgent option before 9.0.8.4 in the management server (aka TSA) component in Alcatel-Lucent OmniTouch Contalcatel-lucent · ccagent · CWE-16 | High7.6 | — | 1.1% | Sep 23, 2010 |
29Monitor | CVE-2024-29149No exploit | An issue was discovered in Alcatel-Lucent ALE NOE deskphones through 86x8_NOE-R300.1.40.12.4180 and SIP deskphones through 86x8_SIP-R200.1.0CWE-367 | High7.4 | — | 0.2% | May 7, 2024 |
28Monitor | CVE-2015-2805Proof of concept | Cross-site request forgery (CSRF) vulnerability in sec/content/sec_asa_users_local_db_add.html in the management web interface in Alcatel-Lualcatel-lucent · omniswitch firmware · CWE-352 | Medium6.8 | — | 3.0% | Jun 16, 2015 |
27Monitor | CVE-2010-3280No exploit | The CCAgent option 9.0.8.4 and earlier in the management server (aka TSA) component in Alcatel-Lucent OmniTouch Contact Center Standard Editalcatel-lucent · ccagent · CWE-200 | Medium6.9 | — | 1.0% | Sep 23, 2010 |
27Monitor | CVE-2015-4586No exploit | Cross-site request forgery (CSRF) vulnerability in Alcatel-Lucent CellPipe 7130 RG 5Ae.M2013 HOL with firmware 1.0.0.20h.HOL allows remote aalcatel-lucent · cellpipe 7130 rg 5ae.m2013 hol firmware · CWE-352 | Medium6.8 | — | 0.9% | Jun 23, 2015 |
24Monitor | CVE-2011-0344No exploit | Multiple stack-based buffer overflows in unspecified CGI programs in the Unified Maintenance Tool web interface in the embedded web server ialcatel-lucent · omnipcx · CWE-119 | Medium5.8 | — | 2.3% | Mar 8, 2011 |
24Monitor | CVE-2002-0293No exploit | FTP service in Alcatel OmniPCX 4400 allows the "halt" user to gain root privileges by modifying root's .profile file.alcatel-lucent · omnipcx | Medium6.2 | — | 0.3% | May 31, 2002 |
22Monitor | CVE-2003-1108No exploit | The Session Initiation Protocol (SIP) implementation in Alcatel OmniPCX Enterprise 5.0 Lx allows remote attackers to cause a denial of servialcatel-lucent · omnipcx | Medium5.0 | — | 5.0% | Dec 31, 2003 |
22Monitor | CVE-2010-3281No exploit | Stack-based buffer overflow in the HTTP proxy service in Alcatel-Lucent OmniVista 4760 server before R5.1.06.03.c_Patch3 allows remote attacalcatel-lucent · omnivista 4760 server · CWE-119 | Medium5.4 | — | 1.9% | Sep 23, 2010 |
21Monitor | CVE-2015-8687No exploit | Multiple cross-site scripting (XSS) vulnerabilities in the Management Console in Alcatel-Lucent Motive Home Device Manager (HDM) before 4.2 alcatel-lucent · motive home device manager · CWE-79 | Medium5.4 | — | 0.6% | Mar 23, 2017 |
18Monitor | CVE-2015-2804No exploit | The management web interface in Alcatel-Lucent OmniSwitch 6450, 6250, 6850E, 9000E, 6400, and 6855 with firmware before 6.6.4.309.R01 and 6.alcatel-lucent · omniswitch firmware · CWE-200 | Medium4.3 | — | 2.0% | Jun 16, 2015 |
18Monitor | CVE-2007-5190Proof of concept | Multiple cross-site scripting (XSS) vulnerabilities in Alcatel OmniVista 4760 R4.2 and earlier allow remote attackers to inject arbitrary wealcatel-lucent · omnivista · CWE-79 | Medium4.3 | — | 2.0% | Oct 22, 2007 |
18Monitor | CVE-2002-0295No exploit | Alcatel OmniPCX 4400 installs files with world-writable permissions, which allows local users to reconfigure the system and possibly gain pralcatel-lucent · omnipcx | Medium4.6 | — | 0.3% | May 31, 2002 |
17Monitor | CVE-2013-4653No exploit | Multiple cross-site scripting (XSS) vulnerabilities in the signin functionality of ics in MyTeamwork services in Alcatel-Lucent Omnitouch 86alcatel-lucent · omnitouch 8400 instant communications suite · CWE-79 | Medium4.3 | — | 1.3% | Aug 19, 2013 |
17Monitor | CVE-2015-4587No exploit | Cross-site scripting (XSS) vulnerability in the Alcatel-Lucent CellPipe 7130 router with firmware 1.0.0.20h.HOL allows remote attackers to ialcatel-lucent · cellpipe 7130 router firmware · CWE-79 | Medium4.3 | — | 1.0% | Jun 18, 2015 |
- CVE-2016-979643Plan
Alcatel-Lucent OmniVista 8770 2.0 through 3.0 exposes different ORBs interfaces, which can be queried using the GIOP protocol on TCP port 30
CriticalCVSS 9.8Proof of conceptEPSS 13%alcatel-lucent · omnivista 8770 network management systemDec 3, 2016
- CVE-2008-133143Plan
cgi-data/FastJSData.cgi in OmniPCX Office with Internet Access services OXO210 before 210/091.001, OXO600 before 610/014.001, and other vers
CriticalCVSS 10.0Proof of conceptEPSS 9%alcatel-lucent · omnipcx officeApr 2, 2008
- CVE-2008-438342Plan
Stack-based buffer overflow in the Agranet-Emweb embedded management web server in Alcatel OmniSwitch OS7000, OS6600, OS6800, OS6850, and OS
CriticalCVSS 10.0No exploitEPSS 8%alcatel · aosOct 3, 2008
- CVE-2002-169141Plan
Alcatel OmniPCX 4400 installs known user accounts and passwords in the /etc/password file by default, which allows remote attackers to gain
CriticalCVSS 10.0No exploitEPSS 4%alcatel-lucent · omnipcxDec 31, 2002
- CVE-2007-182241Plan
Alcatel-Lucent Lucent Technologies voice mail systems allow remote attackers to retrieve or remove messages, or reconfigure mailboxes, by sp
CriticalCVSS 10.0No exploitEPSS 3%alcatel-lucent · voice mail systemApr 2, 2007
- CVE-2007-536135Monitor
The Communication Server in Alcatel-Lucent OmniPCX Enterprise 7.1 and earlier caches an IP address during a TFTP request from an IP Touch ph
HighCVSS 8.5No exploitEPSS 2%alcatel-lucent · omnipcxNov 20, 2007
- CVE-2007-093132Monitor
Heap-based buffer overflow in the management interfaces in (1) Aruba Mobility Controllers 200, 800, 2400, and 6000 and (2) Alcatel-Lucent Om
HighCVSS 7.5No exploitEPSS 6%alcatel-lucent · omniaccess wirelessFeb 14, 2007
- CVE-2007-093231Monitor
The (1) Aruba Mobility Controllers 200, 600, 2400, and 6000 and (2) Alcatel-Lucent OmniAccess Wireless 43xx and 6000 do not properly impleme
HighCVSS 7.5No exploitEPSS 2%alcatel-lucent · omniaccess wirelessFeb 14, 2007
- CVE-2015-649831Monitor
Alcatel-Lucent Home Device Manager before 4.1.10, 4.2.x before 4.2.2 allows remote attackers to spoof and make calls as target devices.
HighCVSS 7.5No exploitEPSS 2%alcatel-lucent · home device managerAug 9, 2017
- CVE-2007-251230Monitor
Alcatel-Lucent IP-Touch Telephone running OmniPCX Enterprise 7.0 and later enables the mini switch by default, which allows attackers to gai
HighCVSS 7.5No exploitEPSS 1%alcatel-lucent · omnipcxJun 7, 2007
- CVE-2010-327930Monitor
The default configuration of the CCAgent option before 9.0.8.4 in the management server (aka TSA) component in Alcatel-Lucent OmniTouch Cont
HighCVSS 7.6No exploitEPSS 1%alcatel-lucent · ccagentSep 23, 2010
- CVE-2024-2914929Monitor
An issue was discovered in Alcatel-Lucent ALE NOE deskphones through 86x8_NOE-R300.1.40.12.4180 and SIP deskphones through 86x8_SIP-R200.1.0
HighCVSS 7.4No exploitEPSS 0%May 7, 2024
- CVE-2015-280528Monitor
Cross-site request forgery (CSRF) vulnerability in sec/content/sec_asa_users_local_db_add.html in the management web interface in Alcatel-Lu
MediumCVSS 6.8Proof of conceptEPSS 3%alcatel-lucent · omniswitch firmwareJun 16, 2015
- CVE-2010-328027Monitor
The CCAgent option 9.0.8.4 and earlier in the management server (aka TSA) component in Alcatel-Lucent OmniTouch Contact Center Standard Edit
MediumCVSS 6.9No exploitEPSS 1%alcatel-lucent · ccagentSep 23, 2010
- CVE-2015-458627Monitor
Cross-site request forgery (CSRF) vulnerability in Alcatel-Lucent CellPipe 7130 RG 5Ae.M2013 HOL with firmware 1.0.0.20h.HOL allows remote a
MediumCVSS 6.8No exploitEPSS 1%alcatel-lucent · cellpipe 7130 rg 5ae.m2013 hol firmwareJun 23, 2015
- CVE-2011-034424Monitor
Multiple stack-based buffer overflows in unspecified CGI programs in the Unified Maintenance Tool web interface in the embedded web server i
MediumCVSS 5.8No exploitEPSS 2%alcatel-lucent · omnipcxMar 8, 2011
- CVE-2002-029324Monitor
FTP service in Alcatel OmniPCX 4400 allows the "halt" user to gain root privileges by modifying root's .profile file.
MediumCVSS 6.2No exploitEPSS 0%alcatel-lucent · omnipcxMay 31, 2002
- CVE-2003-110822Monitor
The Session Initiation Protocol (SIP) implementation in Alcatel OmniPCX Enterprise 5.0 Lx allows remote attackers to cause a denial of servi
MediumCVSS 5.0No exploitEPSS 5%alcatel-lucent · omnipcxDec 31, 2003
- CVE-2010-328122Monitor
Stack-based buffer overflow in the HTTP proxy service in Alcatel-Lucent OmniVista 4760 server before R5.1.06.03.c_Patch3 allows remote attac
MediumCVSS 5.4No exploitEPSS 2%alcatel-lucent · omnivista 4760 serverSep 23, 2010
- CVE-2015-868721Monitor
Multiple cross-site scripting (XSS) vulnerabilities in the Management Console in Alcatel-Lucent Motive Home Device Manager (HDM) before 4.2
MediumCVSS 5.4No exploitEPSS 1%alcatel-lucent · motive home device managerMar 23, 2017
- CVE-2015-280418Monitor
The management web interface in Alcatel-Lucent OmniSwitch 6450, 6250, 6850E, 9000E, 6400, and 6855 with firmware before 6.6.4.309.R01 and 6.
MediumCVSS 4.3No exploitEPSS 2%alcatel-lucent · omniswitch firmwareJun 16, 2015
- CVE-2007-519018Monitor
Multiple cross-site scripting (XSS) vulnerabilities in Alcatel OmniVista 4760 R4.2 and earlier allow remote attackers to inject arbitrary we
MediumCVSS 4.3Proof of conceptEPSS 2%alcatel-lucent · omnivistaOct 22, 2007
- CVE-2002-029518Monitor
Alcatel OmniPCX 4400 installs files with world-writable permissions, which allows local users to reconfigure the system and possibly gain pr
MediumCVSS 4.6No exploitEPSS 0%alcatel-lucent · omnipcxMay 31, 2002
- CVE-2013-465317Monitor
Multiple cross-site scripting (XSS) vulnerabilities in the signin functionality of ics in MyTeamwork services in Alcatel-Lucent Omnitouch 86
MediumCVSS 4.3No exploitEPSS 1%alcatel-lucent · omnitouch 8400 instant communications suiteAug 19, 2013
- CVE-2015-458717Monitor
Cross-site scripting (XSS) vulnerability in the Alcatel-Lucent CellPipe 7130 router with firmware 1.0.0.20h.HOL allows remote attackers to i
MediumCVSS 4.3No exploitEPSS 1%alcatel-lucent · cellpipe 7130 router firmwareJun 18, 2015