CVE-2007-3010

al-enterprise omnipcx enterprise communication server

Published 18 Sept 2007 · updated 16 Jun 2026 · Analyzed

9.8 Critical · CVSS 3.1, NVD

Exploited in the wild

CISA added this to its Known Exploited Vulnerabilities catalog on 15 Apr 2022, with a remediation deadline of 6 May 2022 for US federal agencies.

Required action: Apply updates per vendor instructions.

Description

masterCGI in the Unified Maintenance Tool in Alcatel OmniPCX Enterprise Communication Server R7.1 and earlier allows remote attackers to execute arbitrary commands via shell metacharacters in the user parameter during a ping action.

References