CVE-2019-20048: Malicious File Upload
An issue was discovered on Alcatel-Lucent OmniVista 8770 devices before 4.1.2. An authenticated remote attacker, with elevated privileges in the Web Directory component on port 389, may upload a PHP file to achieve Remote Code Execution as SYSTEM.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2019-20048?
The severity of CVE-2019-20048 is critical with a severity value of 7.2.
What is the affected software of CVE-2019-20048?
The affected software of CVE-2019-20048 is Alcatel-Lucent OmniVista 8770 devices before version 4.1.2.
How can an attacker exploit CVE-2019-20048?
An authenticated remote attacker with elevated privileges in the Web Directory component on port 389 can upload a PHP file to achieve Remote Code Execution as SYSTEM.
Are there any known fixes for CVE-2019-20048?
Yes, upgrading to version 4.1.2 of Alcatel-Lucent OmniVista 8770 devices will fix CVE-2019-20048.
Is there any additional information available about CVE-2019-20048?
Additional information about CVE-2019-20048 can be found in the references provided: [1], [2], [3].