CVE-2019-3920: OS Command Injection
Published Mar 5, 2019
·Updated
The Alcatel Lucent I-240W-Q GPON ONT using firmware version 3FE54567BOZJ19 is vulnerable to authenticated command injection via crafted HTTP request sent by a remote, authenticated attacker to /GponForm/deviceForm?script/.
Affected Software
4 affected components
All of the following
Nokia I-240w-q Gpon Ont Firmware=3fe54567bozj19
Nokia I-240w-q Gpon Ont
Nokia I-240w-q Gpon Ont Firmware=3fe54567bozj19
Nokia I-240w-q Gpon Ont
Event History
Mar 5, 2019
CVE Published
via MITRE·09:00 PM
Data Sourced
via MITRE·09:00 PM
DescriptionWeakness
Data Sourced
via NVD·09:29 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2019-3920?
CVE-2019-3920 is classified as a high severity vulnerability that allows authenticated command injection.
2
How do I fix CVE-2019-3920?
To fix CVE-2019-3920, upgrade the firmware of the Alcatel Lucent I-240W-Q GPON ONT to a secure version beyond 3FE54567BOZJ19.
3
Who is affected by CVE-2019-3920?
CVE-2019-3920 affects users of the Nokia I-240W-Q GPON ONT with firmware version 3FE54567BOZJ19.
4
What type of vulnerability is CVE-2019-3920?
CVE-2019-3920 is an authenticated command injection vulnerability.
5
Can CVE-2019-3920 be exploited remotely?
Yes, CVE-2019-3920 can be exploited remotely by an authenticated attacker through crafted HTTP requests.