CVE-2019-20049: Critical severity al-enterprise omnivista 4760 vulnerability
An issue was discovered on Alcatel-Lucent OmniVista 4760 devices. A remote unauthenticated attacker can chain a directory traversal (which helps to bypass authentication) with an insecure file upload to achieve Remote Code Execution as SYSTEM. The directory traversal is in the construct() whereas the insecure file upload is in SetSkinImages().
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2019-20049.
What is the severity of CVE-2019-20049?
CVE-2019-20049 has a severity rating of 9.8, which is classified as critical.
What is the affected software?
The affected software is Alcatel-Lucent OmniVista 4760.
What is the impact of this vulnerability?
This vulnerability allows a remote unauthenticated attacker to achieve remote code execution as SYSTEM on Alcatel-Lucent OmniVista 4760 devices.
How can this vulnerability be exploited?
An attacker can exploit this vulnerability by chaining a directory traversal with an insecure file upload to bypass authentication and execute arbitrary code.