First published: Fri Dec 27 2019(Updated: )
An issue was discovered on Alcatel-Lucent OmniVista 8770 devices before 4.1.2. An authenticated remote attacker, with elevated privileges in the Web Directory component on port 389, may upload a PHP file to achieve Remote Code Execution as SYSTEM.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Al-enterprise Omnivista 8770 | <4.1.12 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2019-20048 is critical with a severity value of 7.2.
The affected software of CVE-2019-20048 is Alcatel-Lucent OmniVista 8770 devices before version 4.1.2.
An authenticated remote attacker with elevated privileges in the Web Directory component on port 389 can upload a PHP file to achieve Remote Code Execution as SYSTEM.
Yes, upgrading to version 4.1.2 of Alcatel-Lucent OmniVista 8770 devices will fix CVE-2019-20048.
Additional information about CVE-2019-20048 can be found in the references provided: [1], [2], [3].