Description
An issue was discovered on Alcatel-Lucent OmniVista 4760 devices. A remote unauthenticated attacker can chain a directory traversal (which helps to bypass authentication) with an insecure file upload to achieve Remote Code Execution as SYSTEM. The directory traversal is in the __construct() whereas the insecure file upload is in SetSkinImages().
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
No advisories yet.
References
History
No history.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-05T02:32:10.482Z
Reserved: 2019-12-27T00:00:00.000Z
Link: CVE-2019-20049
No data.
Status : Modified
Published: 2019-12-27T19:15:12.723
Modified: 2024-11-21T04:37:57.813
Link: CVE-2019-20049
No data.
OpenCVE Enrichment
No data.
Weaknesses