Description
An issue was discovered in Alcatel-Lucent ALE NOE deskphones through 86x8_NOE-R300.1.40.12.4180 and SIP deskphones through 86x8_SIP-R200.1.01.10.728. Because of a time-of-check time-of-use vulnerability, an authenticated attacker is able to replace the verified firmware image with malicious firmware during the update process.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
No advisories yet.
References
History
Thu, 26 Feb 2026 13:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Alcatel-lucent
Alcatel-lucent ale 20 Alcatel-lucent ale 20h Alcatel-lucent ale 30 Alcatel-lucent ale 300 Alcatel-lucent ale 30h Alcatel-lucent ale 400 Alcatel-lucent ale 500 |
|
| CPEs | cpe:2.3:o:alcatel-lucent:ale_20:-:*:*:*:*:*:*:* cpe:2.3:o:alcatel-lucent:ale_20h:-:*:*:*:*:*:*:* cpe:2.3:o:alcatel-lucent:ale_300:-:*:*:*:*:*:*:* cpe:2.3:o:alcatel-lucent:ale_30:-:*:*:*:*:*:*:* cpe:2.3:o:alcatel-lucent:ale_30h:-:*:*:*:*:*:*:* cpe:2.3:o:alcatel-lucent:ale_400:-:*:*:*:*:*:*:* cpe:2.3:o:alcatel-lucent:ale_500:-:*:*:*:*:*:*:* |
|
| Vendors & Products |
Alcatel-lucent
Alcatel-lucent ale 20 Alcatel-lucent ale 20h Alcatel-lucent ale 30 Alcatel-lucent ale 300 Alcatel-lucent ale 30h Alcatel-lucent ale 400 Alcatel-lucent ale 500 |
|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-02T01:10:53.864Z
Reserved: 2024-03-18T00:00:00.000Z
Link: CVE-2024-29149
Updated: 2024-08-02T01:10:53.864Z
Status : Awaiting Analysis
Published: 2024-05-07T17:15:07.897
Modified: 2024-11-21T09:07:39.100
Link: CVE-2024-29149
No data.
OpenCVE Enrichment
No data.
Weaknesses