Vulnerabilities > CVE-2019-20049 - Unspecified vulnerability in Al-Enterprise Omnivista 4760

047910
CVSS 10.0 - CRITICAL
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
COMPLETE
Integrity impact
COMPLETE
Availability impact
COMPLETE
network
low complexity
al-enterprise
critical

Summary

An issue was discovered on Alcatel-Lucent OmniVista 4760 devices. A remote unauthenticated attacker can chain a directory traversal (which helps to bypass authentication) with an insecure file upload to achieve Remote Code Execution as SYSTEM. The directory traversal is in the __construct() whereas the insecure file upload is in SetSkinImages().

Vulnerable Configurations

Part Description Count
Application
Al-Enterprise
1

Saint

descriptionAlcatel OmniVista remote command execution
idweb_tool_omnivista
titlealcatel_omnivista
typeremote