CVE-2007-3010

Confirmed PUBLISHED

masterCGI in the Unified Maintenance Tool in Alcatel OmniPCX Enterprise Communication Server R7.1 and earlier allows remote attackers to execute...

Alcatel · OmniPCX Enterprise Communication Server
Exploited in the wild PoC available

Recommended Action

Prioritize remediation. Validate affected assets and apply vendor fixes on an accelerated timeline.

Confidence
Confirmed
Exploitation Status
Exploited in the wild
Observed in Sensors
No
Attempts (30d)
Unique Attacker IPs
CISA KEV
In CISA KEV
CVSS / EPSS
9.8 Critical

At a Glance

masterCGI in the Unified Maintenance Tool in Alcatel OmniPCX Enterprise Communication Server R7.1 and earlier allows remote attackers to execute arbitrary commands via shell metacharacters in the user parameter during a ping action.

cisa nuclei_scanner metasploit
CVE Published
Sep 18, 2007
Exploitation Reported
Apr 15, 2022
CVSS
9.8 Critical
EPSS
Remote Low complexity No user interaction Unauthenticated

Affected Versions

Vendor Product Version Status
n/a
n/a

n/a

Affected

CVE References

  • 26853 secunia.com · Third-Party Advisory http://secunia.com/advisories/26853
  • ADV-2007-3185 vupen.com · VDB Entry http://www.vupen.com/english/advisories/2007/3185
  • 40521 osvdb.org · VDB Entry http://osvdb.org/40521
  • alcatel-unified-mastercgi-command-execution(36632) exchange.xforce.ibmcloud.com · VDB Entry https://exchange.xforce.ibmcloud.com/vulnerabilities/36632
  • 25694 securityfocus.com · VDB Entry http://www.securityfocus.com/bid/25694
Show 4 more references

Recommended Actions

  • Prioritize remediation. Validate affected assets and apply vendor fixes on an accelerated timeline.
  • Check enrichment artifacts for scanner coverage and available PoCs before rolling remediation validation.
  • Use the Pro API to automate enrichment, telemetry, and workflow delivery for VM, SOC, and CTI pipelines.