First published: Fri May 03 2002(Updated: )
Alcatel 4400 installs the /chetc/shutdown command with setgid privileges, which allows many different local users to shut down the system.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Alcatel-Lucent OmniPCX | =4400 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2002-0294 has a medium severity rating, primarily due to the potential for unauthorized system shutdown.
To fix CVE-2002-0294, remove the setgid permission from the /chetc/shutdown command or restrict access to trusted users only.
CVE-2002-0294 affects Alcatel Lucent OmniPCX version 4400.
CVE-2002-0294 allows local unauthorized users to shut down affected systems, potentially leading to service disruption.
CVE-2002-0294 is generally not prevalent in modern systems, but older versions of affected software may still exist in some environments.