CVE-2007-3010
al-enterprise omnipcx enterprise communication server
Published 18 Sept 2007 · updated 16 Jun 2026 · Analyzed
9.8 Critical · CVSS 3.1, NVD
Exploited in the wild
CISA added this to its Known Exploited Vulnerabilities catalog on 15 Apr 2022, with a remediation deadline of 6 May 2022 for US federal agencies.
Required action: Apply updates per vendor instructions.
Description
masterCGI in the Unified Maintenance Tool in Alcatel OmniPCX Enterprise Communication Server R7.1 and earlier allows remote attackers to execute arbitrary commands via shell metacharacters in the user parameter during a ping action.
References
- marc.info/?l=full-disclosure&m=119002152126755&w=2 · Exploit, Mailing List
- osvdb.org/40521 · Broken Link
- secunia.com/advisories/26853 · Broken Link, Vendor Advisory
- www.redteam-pentesting.de/advisories/rt-sa-2007-001.php · Broken Link
- www.securityfocus.com/archive/1/479699/100/0/threaded · Broken Link, Third Party Advisory, VDB Entry
- www.securityfocus.com/bid/25694 · Broken Link, Third Party Advisory, VDB Entry
- www.vupen.com/english/advisories/2007/3185 · Broken Link
- www1.alcatel-lucent.com/psirt/statements/2007002/OXEUMT.htm · Broken Link
- exchange.xforce.ibmcloud.com/vulnerabilities/36632 · Third Party Advisory, VDB Entry
- www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2007-3010 · US Government Resource