An issue was discovered on Alcatel-Lucent OmniVista 4760 devices. A remote unauthenticated attacker can chain a directory traversal (which helps to bypass authentication) with an insecure file upload to achieve Remote Code Execution as SYSTEM. The directory traversal is in the __construct() whereas the insecure file upload is in SetSkinImages().
Metrics
Affected Vendors & Products
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
No history.
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-05T02:32:10.482Z
Reserved: 2019-12-27T00:00:00
Link: CVE-2019-20049
No data.
Status : Modified
Published: 2019-12-27T19:15:12.723
Modified: 2024-11-21T04:37:57.813
Link: CVE-2019-20049
No data.
OpenCVE Enrichment
No data.
Weaknesses