Записи Alcatel-Lucent
27 опубликованных записей вендора alcatel-lucent.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 4
- С записью об исправлении
- 0 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')4
- CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer3
- CWE-352 Cross-Site Request Forgery (CSRF)2
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor2
- CWE-264 Permissions, Privileges, and Access Controls2
- CWE-367 Time-of-check Time-of-use (TOCTOU) Race Condition1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
27 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
43В плане | CVE-2016-9796Proof of concept | Alcatel-Lucent OmniVista 8770 2.0 through 3.0 exposes different ORBs interfaces, which can be queried using the GIOP protocol on TCP port 30alcatel-lucent · omnivista 8770 network management system · CWE-264 | Критическая9,8 | — | 13,4 % | 3 дек. 2016 г. |
43В плане | CVE-2008-1331Proof of concept | cgi-data/FastJSData.cgi in OmniPCX Office with Internet Access services OXO210 before 210/091.001, OXO600 before 610/014.001, and other versalcatel-lucent · omnipcx office · CWE-20 | Критическая10,0 | — | 8,8 % | 2 апр. 2008 г. |
42В плане | CVE-2008-4383Эксплойта нет | Stack-based buffer overflow in the Agranet-Emweb embedded management web server in Alcatel OmniSwitch OS7000, OS6600, OS6800, OS6850, and OSalcatel · aos · CWE-119 | Критическая10,0 | — | 8,2 % | 3 окт. 2008 г. |
41В плане | CVE-2002-1691Эксплойта нет | Alcatel OmniPCX 4400 installs known user accounts and passwords in the /etc/password file by default, which allows remote attackers to gain alcatel-lucent · omnipcx | Критическая10,0 | — | 3,6 % | 31 дек. 2002 г. |
41В плане | CVE-2007-1822Эксплойта нет | Alcatel-Lucent Lucent Technologies voice mail systems allow remote attackers to retrieve or remove messages, or reconfigure mailboxes, by spalcatel-lucent · voice mail system | Критическая10,0 | — | 3,1 % | 2 апр. 2007 г. |
35Наблюдать | CVE-2007-5361Эксплойта нет | The Communication Server in Alcatel-Lucent OmniPCX Enterprise 7.1 and earlier caches an IP address during a TFTP request from an IP Touch phalcatel-lucent · omnipcx | Высокая8,5 | — | 2,4 % | 20 нояб. 2007 г. |
32Наблюдать | CVE-2007-0931Эксплойта нет | Heap-based buffer overflow in the management interfaces in (1) Aruba Mobility Controllers 200, 800, 2400, and 6000 and (2) Alcatel-Lucent Omalcatel-lucent · omniaccess wireless | Высокая7,5 | — | 6,1 % | 14 февр. 2007 г. |
31Наблюдать | CVE-2007-0932Эксплойта нет | The (1) Aruba Mobility Controllers 200, 600, 2400, and 6000 and (2) Alcatel-Lucent OmniAccess Wireless 43xx and 6000 do not properly implemealcatel-lucent · omniaccess wireless · CWE-264 | Высокая7,5 | — | 2,3 % | 14 февр. 2007 г. |
31Наблюдать | CVE-2015-6498Эксплойта нет | Alcatel-Lucent Home Device Manager before 4.1.10, 4.2.x before 4.2.2 allows remote attackers to spoof and make calls as target devices.alcatel-lucent · home device manager · CWE-254 | Высокая7,5 | — | 2,2 % | 9 авг. 2017 г. |
30Наблюдать | CVE-2007-2512Эксплойта нет | Alcatel-Lucent IP-Touch Telephone running OmniPCX Enterprise 7.0 and later enables the mini switch by default, which allows attackers to gaialcatel-lucent · omnipcx | Высокая7,5 | — | 1,2 % | 7 июн. 2007 г. |
30Наблюдать | CVE-2010-3279Эксплойта нет | The default configuration of the CCAgent option before 9.0.8.4 in the management server (aka TSA) component in Alcatel-Lucent OmniTouch Contalcatel-lucent · ccagent · CWE-16 | Высокая7,6 | — | 1,1 % | 23 сент. 2010 г. |
29Наблюдать | CVE-2024-29149Эксплойта нет | An issue was discovered in Alcatel-Lucent ALE NOE deskphones through 86x8_NOE-R300.1.40.12.4180 and SIP deskphones through 86x8_SIP-R200.1.0CWE-367 | Высокая7,4 | — | 0,2 % | 7 мая 2024 г. |
28Наблюдать | CVE-2015-2805Proof of concept | Cross-site request forgery (CSRF) vulnerability in sec/content/sec_asa_users_local_db_add.html in the management web interface in Alcatel-Lualcatel-lucent · omniswitch firmware · CWE-352 | Средняя6,8 | — | 3,0 % | 16 июн. 2015 г. |
27Наблюдать | CVE-2010-3280Эксплойта нет | The CCAgent option 9.0.8.4 and earlier in the management server (aka TSA) component in Alcatel-Lucent OmniTouch Contact Center Standard Editalcatel-lucent · ccagent · CWE-200 | Средняя6,9 | — | 1,0 % | 23 сент. 2010 г. |
27Наблюдать | CVE-2015-4586Эксплойта нет | Cross-site request forgery (CSRF) vulnerability in Alcatel-Lucent CellPipe 7130 RG 5Ae.M2013 HOL with firmware 1.0.0.20h.HOL allows remote aalcatel-lucent · cellpipe 7130 rg 5ae.m2013 hol firmware · CWE-352 | Средняя6,8 | — | 0,9 % | 23 июн. 2015 г. |
24Наблюдать | CVE-2011-0344Эксплойта нет | Multiple stack-based buffer overflows in unspecified CGI programs in the Unified Maintenance Tool web interface in the embedded web server ialcatel-lucent · omnipcx · CWE-119 | Средняя5,8 | — | 2,3 % | 8 мар. 2011 г. |
24Наблюдать | CVE-2002-0293Эксплойта нет | FTP service in Alcatel OmniPCX 4400 allows the "halt" user to gain root privileges by modifying root's .profile file.alcatel-lucent · omnipcx | Средняя6,2 | — | 0,3 % | 31 мая 2002 г. |
22Наблюдать | CVE-2003-1108Эксплойта нет | The Session Initiation Protocol (SIP) implementation in Alcatel OmniPCX Enterprise 5.0 Lx allows remote attackers to cause a denial of servialcatel-lucent · omnipcx | Средняя5,0 | — | 5,0 % | 31 дек. 2003 г. |
22Наблюдать | CVE-2010-3281Эксплойта нет | Stack-based buffer overflow in the HTTP proxy service in Alcatel-Lucent OmniVista 4760 server before R5.1.06.03.c_Patch3 allows remote attacalcatel-lucent · omnivista 4760 server · CWE-119 | Средняя5,4 | — | 1,9 % | 23 сент. 2010 г. |
21Наблюдать | CVE-2015-8687Эксплойта нет | Multiple cross-site scripting (XSS) vulnerabilities in the Management Console in Alcatel-Lucent Motive Home Device Manager (HDM) before 4.2 alcatel-lucent · motive home device manager · CWE-79 | Средняя5,4 | — | 0,6 % | 23 мар. 2017 г. |
18Наблюдать | CVE-2015-2804Эксплойта нет | The management web interface in Alcatel-Lucent OmniSwitch 6450, 6250, 6850E, 9000E, 6400, and 6855 with firmware before 6.6.4.309.R01 and 6.alcatel-lucent · omniswitch firmware · CWE-200 | Средняя4,3 | — | 2,0 % | 16 июн. 2015 г. |
18Наблюдать | CVE-2007-5190Proof of concept | Multiple cross-site scripting (XSS) vulnerabilities in Alcatel OmniVista 4760 R4.2 and earlier allow remote attackers to inject arbitrary wealcatel-lucent · omnivista · CWE-79 | Средняя4,3 | — | 2,0 % | 22 окт. 2007 г. |
18Наблюдать | CVE-2002-0295Эксплойта нет | Alcatel OmniPCX 4400 installs files with world-writable permissions, which allows local users to reconfigure the system and possibly gain pralcatel-lucent · omnipcx | Средняя4,6 | — | 0,3 % | 31 мая 2002 г. |
17Наблюдать | CVE-2013-4653Эксплойта нет | Multiple cross-site scripting (XSS) vulnerabilities in the signin functionality of ics in MyTeamwork services in Alcatel-Lucent Omnitouch 86alcatel-lucent · omnitouch 8400 instant communications suite · CWE-79 | Средняя4,3 | — | 1,3 % | 19 авг. 2013 г. |
17Наблюдать | CVE-2015-4587Эксплойта нет | Cross-site scripting (XSS) vulnerability in the Alcatel-Lucent CellPipe 7130 router with firmware 1.0.0.20h.HOL allows remote attackers to ialcatel-lucent · cellpipe 7130 router firmware · CWE-79 | Средняя4,3 | — | 1,0 % | 18 июн. 2015 г. |
- CVE-2016-979643В плане
Alcatel-Lucent OmniVista 8770 2.0 through 3.0 exposes different ORBs interfaces, which can be queried using the GIOP protocol on TCP port 30
КритическаяCVSS 9,8Proof of conceptEPSS 13 %alcatel-lucent · omnivista 8770 network management system3 дек. 2016 г.
- CVE-2008-133143В плане
cgi-data/FastJSData.cgi in OmniPCX Office with Internet Access services OXO210 before 210/091.001, OXO600 before 610/014.001, and other vers
КритическаяCVSS 10,0Proof of conceptEPSS 9 %alcatel-lucent · omnipcx office2 апр. 2008 г.
- CVE-2008-438342В плане
Stack-based buffer overflow in the Agranet-Emweb embedded management web server in Alcatel OmniSwitch OS7000, OS6600, OS6800, OS6850, and OS
КритическаяCVSS 10,0Эксплойта нетEPSS 8 %alcatel · aos3 окт. 2008 г.
- CVE-2002-169141В плане
Alcatel OmniPCX 4400 installs known user accounts and passwords in the /etc/password file by default, which allows remote attackers to gain
КритическаяCVSS 10,0Эксплойта нетEPSS 4 %alcatel-lucent · omnipcx31 дек. 2002 г.
- CVE-2007-182241В плане
Alcatel-Lucent Lucent Technologies voice mail systems allow remote attackers to retrieve or remove messages, or reconfigure mailboxes, by sp
КритическаяCVSS 10,0Эксплойта нетEPSS 3 %alcatel-lucent · voice mail system2 апр. 2007 г.
- CVE-2007-536135Наблюдать
The Communication Server in Alcatel-Lucent OmniPCX Enterprise 7.1 and earlier caches an IP address during a TFTP request from an IP Touch ph
ВысокаяCVSS 8,5Эксплойта нетEPSS 2 %alcatel-lucent · omnipcx20 нояб. 2007 г.
- CVE-2007-093132Наблюдать
Heap-based buffer overflow in the management interfaces in (1) Aruba Mobility Controllers 200, 800, 2400, and 6000 and (2) Alcatel-Lucent Om
ВысокаяCVSS 7,5Эксплойта нетEPSS 6 %alcatel-lucent · omniaccess wireless14 февр. 2007 г.
- CVE-2007-093231Наблюдать
The (1) Aruba Mobility Controllers 200, 600, 2400, and 6000 and (2) Alcatel-Lucent OmniAccess Wireless 43xx and 6000 do not properly impleme
ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %alcatel-lucent · omniaccess wireless14 февр. 2007 г.
- CVE-2015-649831Наблюдать
Alcatel-Lucent Home Device Manager before 4.1.10, 4.2.x before 4.2.2 allows remote attackers to spoof and make calls as target devices.
ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %alcatel-lucent · home device manager9 авг. 2017 г.
- CVE-2007-251230Наблюдать
Alcatel-Lucent IP-Touch Telephone running OmniPCX Enterprise 7.0 and later enables the mini switch by default, which allows attackers to gai
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %alcatel-lucent · omnipcx7 июн. 2007 г.
- CVE-2010-327930Наблюдать
The default configuration of the CCAgent option before 9.0.8.4 in the management server (aka TSA) component in Alcatel-Lucent OmniTouch Cont
ВысокаяCVSS 7,6Эксплойта нетEPSS 1 %alcatel-lucent · ccagent23 сент. 2010 г.
- CVE-2024-2914929Наблюдать
An issue was discovered in Alcatel-Lucent ALE NOE deskphones through 86x8_NOE-R300.1.40.12.4180 and SIP deskphones through 86x8_SIP-R200.1.0
ВысокаяCVSS 7,4Эксплойта нетEPSS 0 %7 мая 2024 г.
- CVE-2015-280528Наблюдать
Cross-site request forgery (CSRF) vulnerability in sec/content/sec_asa_users_local_db_add.html in the management web interface in Alcatel-Lu
СредняяCVSS 6,8Proof of conceptEPSS 3 %alcatel-lucent · omniswitch firmware16 июн. 2015 г.
- CVE-2010-328027Наблюдать
The CCAgent option 9.0.8.4 and earlier in the management server (aka TSA) component in Alcatel-Lucent OmniTouch Contact Center Standard Edit
СредняяCVSS 6,9Эксплойта нетEPSS 1 %alcatel-lucent · ccagent23 сент. 2010 г.
- CVE-2015-458627Наблюдать
Cross-site request forgery (CSRF) vulnerability in Alcatel-Lucent CellPipe 7130 RG 5Ae.M2013 HOL with firmware 1.0.0.20h.HOL allows remote a
СредняяCVSS 6,8Эксплойта нетEPSS 1 %alcatel-lucent · cellpipe 7130 rg 5ae.m2013 hol firmware23 июн. 2015 г.
- CVE-2011-034424Наблюдать
Multiple stack-based buffer overflows in unspecified CGI programs in the Unified Maintenance Tool web interface in the embedded web server i
СредняяCVSS 5,8Эксплойта нетEPSS 2 %alcatel-lucent · omnipcx8 мар. 2011 г.
- CVE-2002-029324Наблюдать
FTP service in Alcatel OmniPCX 4400 allows the "halt" user to gain root privileges by modifying root's .profile file.
СредняяCVSS 6,2Эксплойта нетEPSS 0 %alcatel-lucent · omnipcx31 мая 2002 г.
- CVE-2003-110822Наблюдать
The Session Initiation Protocol (SIP) implementation in Alcatel OmniPCX Enterprise 5.0 Lx allows remote attackers to cause a denial of servi
СредняяCVSS 5,0Эксплойта нетEPSS 5 %alcatel-lucent · omnipcx31 дек. 2003 г.
- CVE-2010-328122Наблюдать
Stack-based buffer overflow in the HTTP proxy service in Alcatel-Lucent OmniVista 4760 server before R5.1.06.03.c_Patch3 allows remote attac
СредняяCVSS 5,4Эксплойта нетEPSS 2 %alcatel-lucent · omnivista 4760 server23 сент. 2010 г.
- CVE-2015-868721Наблюдать
Multiple cross-site scripting (XSS) vulnerabilities in the Management Console in Alcatel-Lucent Motive Home Device Manager (HDM) before 4.2
СредняяCVSS 5,4Эксплойта нетEPSS 1 %alcatel-lucent · motive home device manager23 мар. 2017 г.
- CVE-2015-280418Наблюдать
The management web interface in Alcatel-Lucent OmniSwitch 6450, 6250, 6850E, 9000E, 6400, and 6855 with firmware before 6.6.4.309.R01 and 6.
СредняяCVSS 4,3Эксплойта нетEPSS 2 %alcatel-lucent · omniswitch firmware16 июн. 2015 г.
- CVE-2007-519018Наблюдать
Multiple cross-site scripting (XSS) vulnerabilities in Alcatel OmniVista 4760 R4.2 and earlier allow remote attackers to inject arbitrary we
СредняяCVSS 4,3Proof of conceptEPSS 2 %alcatel-lucent · omnivista22 окт. 2007 г.
- CVE-2002-029518Наблюдать
Alcatel OmniPCX 4400 installs files with world-writable permissions, which allows local users to reconfigure the system and possibly gain pr
СредняяCVSS 4,6Эксплойта нетEPSS 0 %alcatel-lucent · omnipcx31 мая 2002 г.
- CVE-2013-465317Наблюдать
Multiple cross-site scripting (XSS) vulnerabilities in the signin functionality of ics in MyTeamwork services in Alcatel-Lucent Omnitouch 86
СредняяCVSS 4,3Эксплойта нетEPSS 1 %alcatel-lucent · omnitouch 8400 instant communications suite19 авг. 2013 г.
- CVE-2015-458717Наблюдать
Cross-site scripting (XSS) vulnerability in the Alcatel-Lucent CellPipe 7130 router with firmware 1.0.0.20h.HOL allows remote attackers to i
СредняяCVSS 4,3Эксплойта нетEPSS 1 %alcatel-lucent · cellpipe 7130 router firmware18 июн. 2015 г.