Description
An issue was discovered on Alcatel-Lucent OmniVista 4760 devices. A remote unauthenticated attacker can chain a directory traversal (which helps to bypass authentication) with an insecure file upload to achieve Remote Code Execution as SYSTEM. The directory traversal is in the __construct() whereas the insecure file upload is in SetSkinImages().
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
No advisories yet.
References
History
No history.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-05T02:32:10.482Z
Reserved: 2019-12-27T00:00:00.000Z
Link: CVE-2019-20049
No data.
Status : Modified
Published: 2019-12-27T19:15:12.723
Modified: 2024-11-21T04:37:57.813
Link: CVE-2019-20049
No data.
OpenCVE Enrichment
No data.
Weaknesses