peter bassill · operator
$ cve CVE-2007-3010 JSON

CVE-2007-3010 KEV EXPLOIT

9.8
CRITICAL · CVSS 3.1 · EPSS 97.4% (pctl 100)

Patch first

On CISA KEV — known exploited in the wild, due 2022-05-06.

Description

masterCGI in the Unified Maintenance Tool in Alcatel OmniPCX Enterprise Communication Server R7.1 and earlier allows remote attackers to execute arbitrary commands via shell metacharacters in the user parameter during a ping action.

Scoring

CVSS9.8 (CRITICAL, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS97.39% — more likely to be exploited than 100% of all CVEs
WeaknessCWE-77
On CISA KEVyes — remediate by 2022-05-06
Public exploityes
Published2007-09-18
Last modified2026-06-16

CISA KEV

NameAlcatel OmniPCX Enterprise Remote Code Execution Vulnerability
Added2022-04-15
Due2022-05-06
Vendor / productAlcatel / OmniPCX Enterprise
Ransomware usenone reported

Affected (1)

VendorProduct
al-enterpriseomnipcx enterprise communication server

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD