CVE-2016-9796
critical · 9.8Alcatel-Lucent OmniVista 8770 2.0 through 3.0 exposes different ORBs interfaces, which can be queried using the GIOP protocol on TCP port 30024. An attacker can bypass authentication, and OmniVista invokes methods (AddJobSet, AddJob, and ExecuteNow) that can be used to run arbitrary commands on the server, with the privilege of NT AUTHORITY\SYSTEM on the server. NOTE: The discoverer states "The vendor position is to refer to the technical guidelines of the product security deployment to mitigate this issue, which means applying proper firewall rules to prevent unauthorised clients to connect to the OmniVista server."
9.8
CVSS
13.4%
EPSS (exploit prob.)
96th
EPSS percentile
2016-12-03
Published
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Weaknesses
CWE-264CWE-287
Affected products
| Vendor | Product | Affected versions |
|---|---|---|
| alcatel-lucent | omnivista_8770_network_management_system | 2.0 |
| alcatel-lucent | omnivista_8770_network_management_system | 2.6 |
| alcatel-lucent | omnivista_8770_network_management_system | 3.0 |
Check a specific version with /api/v1/cve/match.
References
- http://blog.malerisch.net/2016/12/alcatel-omnivista-8770-unauth-rce-giop-corba.html
- http://www.securityfocus.com/bid/94649
- https://github.com/malerisch/omnivista-8770-unauth-rce
- https://www.exploit-db.com/exploits/40862/
- https://www.youtube.com/watch?v=aq37lQKa9sk
- http://blog.malerisch.net/2016/12/alcatel-omnivista-8770-unauth-rce-giop-corba.html
- http://www.securityfocus.com/bid/94649
- https://github.com/malerisch/omnivista-8770-unauth-rce
- https://www.exploit-db.com/exploits/40862/
- https://www.youtube.com/watch?v=aq37lQKa9sk
Query this programmatically:
curl https://evil-db.io/api/v1/cve/CVE-2016-9796