RULE(RULE ID:322250)

Rule General Information
Release Date: 2019-07-04
Rule Name: Alcatel OmniPCX Office MasterCGI user Parameter Command Execution Vulnerability (CVE-2007-3010)
Severity:
CVE ID:
Rule Protection Details
Description: masterCGI in the Unified Maintenance Tool in Alcatel OmniPCX Enterprise Communication Server R7.1 and earlier allows remote attackers to execute arbitrary commands via shell metacharacters in the user parameter during a ping action.
Impact: An attacker can execute arbitrary command via a successful exploit in the context of the vulnerable software.
Affected OS: Windows, Linux, FreeBSD, Solaris, Other Unix, Network Device, Mac OS, iOS, Android, Others
Reference: SecurityFocusBID:25694
http://marc.info/?l=full-disclosure&m=119002152126755&w=2
http://www.redteam-pentesting.de/advisories/rt-sa-2007-001.php
http://www.securityfocus.com/archive/1/479699/100/0/threaded
Solutions
The vendors have released upgrade patches to fix vulnerabilities, please visit:
http://www1.alcatel-lucent.com/enterprise/en/products/phones/index.html