An issue was discovered on Alcatel-Lucent OmniVista 4760 devices. A remote unauthenticated attacker can chain a directory traversal (which helps to bypass authentication) with an insecure file upload to achieve Remote Code Execution as SYSTEM. The directory traversal is in the __construct() whereas the insecure file upload is in SetSkinImages().
Advisories

No advisories yet.

Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2024-08-05T02:32:10.482Z

Reserved: 2019-12-27T00:00:00

Link: CVE-2019-20049

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2019-12-27T19:15:12.723

Modified: 2024-11-21T04:37:57.813

Link: CVE-2019-20049

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.