CVE-2007-3010 KEV EXPLOIT
9.8
CRITICAL · CVSS 3.1 · EPSS 97.4% (pctl 100)
Patch first
On CISA KEV — known exploited in the wild, due 2022-05-06.
Description
masterCGI in the Unified Maintenance Tool in Alcatel OmniPCX Enterprise Communication Server R7.1 and earlier allows remote attackers to execute arbitrary commands via shell metacharacters in the user parameter during a ping action.
Scoring
| CVSS | 9.8 (CRITICAL, v3.1) |
|---|---|
| Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| EPSS | 97.39% — more likely to be exploited than 100% of all CVEs |
| Weakness | CWE-77 |
| On CISA KEV | yes — remediate by 2022-05-06 |
| Public exploit | yes |
| Published | 2007-09-18 |
| Last modified | 2026-06-16 |
CISA KEV
| Name | Alcatel OmniPCX Enterprise Remote Code Execution Vulnerability |
|---|---|
| Added | 2022-04-15 |
| Due | 2022-05-06 |
| Vendor / product | Alcatel / OmniPCX Enterprise |
| Ransomware use | none reported |
Affected (1)
| Vendor | Product |
|---|---|
| al-enterprise | omnipcx enterprise communication server |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | Alcatel-Lucent OmniPCX Enterprise - masterCGI Arbitrary Command Execution (Metasploit) | 2010-10-05 |
| exploit-db | Alcatel-Lucent OmniPCX Enterprise Communication Server 7.1 - masterCGI Command Injection (Metasploit) | 2007-09-17 |
| exploit-db | Alcatel-Lucent OmniPCX Enterprise 7.1 - Remote Command Execution | 2007-09-17 |
References
- http://marc.info/?l=full-disclosure&m=119002152126755&w=2
- http://osvdb.org/40521
- http://secunia.com/advisories/26853
- http://www.redteam-pentesting.de/advisories/rt-sa-2007-001.php
- http://www.securityfocus.com/archive/1/479699/100/0/threaded
- http://www.securityfocus.com/bid/25694
- http://www.vupen.com/english/advisories/2007/3185
- http://www1.alcatel-lucent.com/psirt/statements/2007002/OXEUMT.htm
- https://exchange.xforce.ibmcloud.com/vulnerabilities/36632
- http://marc.info/?l=full-disclosure&m=119002152126755&w=2
- http://osvdb.org/40521
- http://secunia.com/advisories/26853
- http://www.redteam-pentesting.de/advisories/rt-sa-2007-001.php
- http://www.securityfocus.com/archive/1/479699/100/0/threaded
- http://www.securityfocus.com/bid/25694
- http://www.vupen.com/english/advisories/2007/3185
- http://www1.alcatel-lucent.com/psirt/statements/2007002/OXEUMT.htm
- https://exchange.xforce.ibmcloud.com/vulnerabilities/36632
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2007-3010
→ the Explorer · watch your stack · NVD