CVE-2019-20048

Severity CVSS v4.0:
Pending analysis
Type:
CWE-434 Unrestricted Upload of File with Dangerous Type
Publication date:
27/12/2019
Last modified:
07/01/2020

Description

An issue was discovered on Alcatel-Lucent OmniVista 8770 devices before 4.1.2. An authenticated remote attacker, with elevated privileges in the Web Directory component on port 389, may upload a PHP file to achieve Remote Code Execution as SYSTEM.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:al-enterprise:omnivista_8770:*:*:*:*:*:*:*:* 4.1.12 (excluding)