Vulnerability detail
Enriched intelligence for a single CVE
Critical
CVE-2007-3010
PUBLISHEDmasterCGI in the Unified Maintenance Tool in Alcatel OmniPCX Enterprise Communication Server R7.1 and earlier allows remote attackers to execute...
- Vendor
- Alcatel
- Product
- OmniPCX Enterprise Communication Server
- Published
- Sep 18, 2007
- EPSS
- —
Description
masterCGI in the Unified Maintenance Tool in Alcatel OmniPCX Enterprise Communication Server R7.1 and earlier allows remote attackers to execute arbitrary commands via shell metacharacters in the user parameter during a ping action.
CVSS scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
AV:N/AC:L/Au:N/C:C/I:C/A:C
Exploitation status
Exploited in the wild
Recorded 2022-04-15 00:00:00 UTC · Source
SSVC decision points
- Exploitation
- active
- Automatable
- Yes
- Technical impact
- total
References
- http://www.vupen.com/english/advisories/2007/3185
- http://www.redteam-pentesting.de/advisories/rt-sa-2007-001.php
- http://www1.alcatel-lucent.com/psirt/statements/2007002/OXEUMT.htm
- http://secunia.com/advisories/26853
- http://marc.info/?l=full-disclosure&m=119002152126755&w=2
- http://osvdb.org/40521
- http://www.securityfocus.com/archive/1/479699/100/0/threaded
- https://exchange.xforce.ibmcloud.com/vulnerabilities/36632
- http://www.securityfocus.com/bid/25694
Known exploited vulnerability sources
Catalogues that list this CVE as a known exploited vulnerability.
| Source | Added |
|---|---|
| CISA | Apr 15, 2022 |
Scanner integrations
| Scanner | Reference | Detected |
|---|---|---|
| Metasploit | https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/linux/http/alcatel_omnipcx_mastercgi_exec.rb | Apr 28, 2025 |
| Nuclei | https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2007/CVE-2007-3010.yaml | Apr 25, 2025 |
Potential proof of concepts
These PoCs are unverified and could contain malware. Use at your own risk.
Timeline
-
CVE ID Reserved
-
CVE Published to Public
-
Added to KEVIntel
-
Detected by Nuclei
-
Detected by Metasploit