First published: Fri May 03 2002(Updated: )
FTP service in Alcatel OmniPCX 4400 allows the "halt" user to gain root privileges by modifying root's .profile file.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Alcatel-Lucent OmniPCX | =4400 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2002-0293 is classified as a high-severity vulnerability due to its potential for unauthorized root access.
To fix CVE-2002-0293, restrict FTP access for the 'halt' user and ensure the root user's .profile file is secure.
CVE-2002-0293 affects the Alcatel OmniPCX 4400 FTP service specifically.
The implications of CVE-2002-0293 include potential full system compromise due to unauthorized root access.
You can verify your vulnerability to CVE-2002-0293 by checking the FTP service configuration and permissions for the 'halt' user.