CVE-2008-4383
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
Stack-based buffer overflow in the Agranet-Emweb embedded management web server in Alcatel OmniSwitch OS7000, OS6600, OS6800, OS6850, and OS9000 Series devices with AoS 5.1 before 5.1.6.463.R02, 5.4 before 5.4.1.429.R01, 6.1.3 before 6.1.3.965.R01, 6.1.5 before 6.1.5.595.R01, and 6.3 before 6.3.1.966.R01 allows remote attackers to execute arbitrary code via a long Session cookie.
Desbordamiento de búfer basado en pila en el servidor web de gestión embebido Agranet-Emweb de Alcatel OmniSwitch dispositivos OS7000, OS6600, OS6800, OS6850, y OS9000 Series con AoS 5.1 versiones anteriores a v5.1.6.463.R02, 5.4 versiones anteriores a v5.4.1.429.R01, 6.1.3 versiones anteriores a v6.1.3.965.R01, 6.1.5 versiones anteriores a v6.1.5.595.R01, y 6.3 versiones anteriores a v6.3.1.966.R01 permite a atacantes remotos ejecutar código de su elección a través de una cookie Session.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2008-10-02 CVE Reserved
- 2008-10-03 CVE Published
- 2023-03-07 EPSS Updated
- 2024-08-07 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer
CAPEC
References (9)
URL | Tag | Source |
---|---|---|
http://secunia.com/advisories/31435 | Third Party Advisory | |
http://securityreason.com/securityalert/4347 | Third Party Advisory | |
http://www.layereddefense.com/alcatel12aug.html | Broken Link | |
http://www.securityfocus.com/archive/1/495343/100/0/threaded | Mailing List | |
http://www.securityfocus.com/bid/30652 | Third Party Advisory | |
http://www.securitytracker.com/id?1020657 | Third Party Advisory | |
http://www.vupen.com/english/advisories/2008/2346 | Third Party Advisory | |
https://exchange.xforce.ibmcloud.com/vulnerabilities/44400 | Third Party Advisory |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
http://www1.alcatel-lucent.com/psirt/statements/2008002/OmniSwitch.htm | 2018-11-02 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Alcatel Search vendor "Alcatel" | Aos Search vendor "Alcatel" for product "Aos" | >= 5.1 < 5.1.6.463.r02 Search vendor "Alcatel" for product "Aos" and version " >= 5.1 < 5.1.6.463.r02" | - |
Affected
| in | Alcatel-lucent Search vendor "Alcatel-lucent" | Omniswitch Search vendor "Alcatel-lucent" for product "Omniswitch" | os6600 Search vendor "Alcatel-lucent" for product "Omniswitch" and version "os6600" | - |
Safe
|
Alcatel Search vendor "Alcatel" | Aos Search vendor "Alcatel" for product "Aos" | >= 5.1 < 5.1.6.463.r02 Search vendor "Alcatel" for product "Aos" and version " >= 5.1 < 5.1.6.463.r02" | - |
Affected
| in | Alcatel-lucent Search vendor "Alcatel-lucent" | Omniswitch Search vendor "Alcatel-lucent" for product "Omniswitch" | os6800 Search vendor "Alcatel-lucent" for product "Omniswitch" and version "os6800" | - |
Safe
|
Alcatel Search vendor "Alcatel" | Aos Search vendor "Alcatel" for product "Aos" | >= 5.1 < 5.1.6.463.r02 Search vendor "Alcatel" for product "Aos" and version " >= 5.1 < 5.1.6.463.r02" | - |
Affected
| in | Alcatel-lucent Search vendor "Alcatel-lucent" | Omniswitch Search vendor "Alcatel-lucent" for product "Omniswitch" | os6850 Search vendor "Alcatel-lucent" for product "Omniswitch" and version "os6850" | - |
Safe
|
Alcatel Search vendor "Alcatel" | Aos Search vendor "Alcatel" for product "Aos" | >= 5.1 < 5.1.6.463.r02 Search vendor "Alcatel" for product "Aos" and version " >= 5.1 < 5.1.6.463.r02" | - |
Affected
| in | Alcatel-lucent Search vendor "Alcatel-lucent" | Omniswitch Search vendor "Alcatel-lucent" for product "Omniswitch" | os7000 Search vendor "Alcatel-lucent" for product "Omniswitch" and version "os7000" | - |
Safe
|
Alcatel Search vendor "Alcatel" | Aos Search vendor "Alcatel" for product "Aos" | >= 5.1 < 5.1.6.463.r02 Search vendor "Alcatel" for product "Aos" and version " >= 5.1 < 5.1.6.463.r02" | - |
Affected
| in | Alcatel-lucent Search vendor "Alcatel-lucent" | Omniswitch Search vendor "Alcatel-lucent" for product "Omniswitch" | os9000 Search vendor "Alcatel-lucent" for product "Omniswitch" and version "os9000" | - |
Safe
|
Alcatel Search vendor "Alcatel" | Aos Search vendor "Alcatel" for product "Aos" | >= 5.4 < 5.4.1.429.r01 Search vendor "Alcatel" for product "Aos" and version " >= 5.4 < 5.4.1.429.r01" | - |
Affected
| in | Alcatel-lucent Search vendor "Alcatel-lucent" | Omniswitch Search vendor "Alcatel-lucent" for product "Omniswitch" | os6600 Search vendor "Alcatel-lucent" for product "Omniswitch" and version "os6600" | - |
Safe
|
Alcatel Search vendor "Alcatel" | Aos Search vendor "Alcatel" for product "Aos" | >= 5.4 < 5.4.1.429.r01 Search vendor "Alcatel" for product "Aos" and version " >= 5.4 < 5.4.1.429.r01" | - |
Affected
| in | Alcatel-lucent Search vendor "Alcatel-lucent" | Omniswitch Search vendor "Alcatel-lucent" for product "Omniswitch" | os6800 Search vendor "Alcatel-lucent" for product "Omniswitch" and version "os6800" | - |
Safe
|
Alcatel Search vendor "Alcatel" | Aos Search vendor "Alcatel" for product "Aos" | >= 5.4 < 5.4.1.429.r01 Search vendor "Alcatel" for product "Aos" and version " >= 5.4 < 5.4.1.429.r01" | - |
Affected
| in | Alcatel-lucent Search vendor "Alcatel-lucent" | Omniswitch Search vendor "Alcatel-lucent" for product "Omniswitch" | os6850 Search vendor "Alcatel-lucent" for product "Omniswitch" and version "os6850" | - |
Safe
|
Alcatel Search vendor "Alcatel" | Aos Search vendor "Alcatel" for product "Aos" | >= 5.4 < 5.4.1.429.r01 Search vendor "Alcatel" for product "Aos" and version " >= 5.4 < 5.4.1.429.r01" | - |
Affected
| in | Alcatel-lucent Search vendor "Alcatel-lucent" | Omniswitch Search vendor "Alcatel-lucent" for product "Omniswitch" | os7000 Search vendor "Alcatel-lucent" for product "Omniswitch" and version "os7000" | - |
Safe
|
Alcatel Search vendor "Alcatel" | Aos Search vendor "Alcatel" for product "Aos" | >= 5.4 < 5.4.1.429.r01 Search vendor "Alcatel" for product "Aos" and version " >= 5.4 < 5.4.1.429.r01" | - |
Affected
| in | Alcatel-lucent Search vendor "Alcatel-lucent" | Omniswitch Search vendor "Alcatel-lucent" for product "Omniswitch" | os9000 Search vendor "Alcatel-lucent" for product "Omniswitch" and version "os9000" | - |
Safe
|
Alcatel Search vendor "Alcatel" | Aos Search vendor "Alcatel" for product "Aos" | >= 6.1.3 < 6.1.3.965.r01 Search vendor "Alcatel" for product "Aos" and version " >= 6.1.3 < 6.1.3.965.r01" | - |
Affected
| in | Alcatel-lucent Search vendor "Alcatel-lucent" | Omniswitch Search vendor "Alcatel-lucent" for product "Omniswitch" | os6600 Search vendor "Alcatel-lucent" for product "Omniswitch" and version "os6600" | - |
Safe
|
Alcatel Search vendor "Alcatel" | Aos Search vendor "Alcatel" for product "Aos" | >= 6.1.3 < 6.1.3.965.r01 Search vendor "Alcatel" for product "Aos" and version " >= 6.1.3 < 6.1.3.965.r01" | - |
Affected
| in | Alcatel-lucent Search vendor "Alcatel-lucent" | Omniswitch Search vendor "Alcatel-lucent" for product "Omniswitch" | os6800 Search vendor "Alcatel-lucent" for product "Omniswitch" and version "os6800" | - |
Safe
|
Alcatel Search vendor "Alcatel" | Aos Search vendor "Alcatel" for product "Aos" | >= 6.1.3 < 6.1.3.965.r01 Search vendor "Alcatel" for product "Aos" and version " >= 6.1.3 < 6.1.3.965.r01" | - |
Affected
| in | Alcatel-lucent Search vendor "Alcatel-lucent" | Omniswitch Search vendor "Alcatel-lucent" for product "Omniswitch" | os6850 Search vendor "Alcatel-lucent" for product "Omniswitch" and version "os6850" | - |
Safe
|
Alcatel Search vendor "Alcatel" | Aos Search vendor "Alcatel" for product "Aos" | >= 6.1.3 < 6.1.3.965.r01 Search vendor "Alcatel" for product "Aos" and version " >= 6.1.3 < 6.1.3.965.r01" | - |
Affected
| in | Alcatel-lucent Search vendor "Alcatel-lucent" | Omniswitch Search vendor "Alcatel-lucent" for product "Omniswitch" | os7000 Search vendor "Alcatel-lucent" for product "Omniswitch" and version "os7000" | - |
Safe
|
Alcatel Search vendor "Alcatel" | Aos Search vendor "Alcatel" for product "Aos" | >= 6.1.3 < 6.1.3.965.r01 Search vendor "Alcatel" for product "Aos" and version " >= 6.1.3 < 6.1.3.965.r01" | - |
Affected
| in | Alcatel-lucent Search vendor "Alcatel-lucent" | Omniswitch Search vendor "Alcatel-lucent" for product "Omniswitch" | os9000 Search vendor "Alcatel-lucent" for product "Omniswitch" and version "os9000" | - |
Safe
|
Alcatel Search vendor "Alcatel" | Aos Search vendor "Alcatel" for product "Aos" | >= 6.1.5 < 6.1.5.595.r01 Search vendor "Alcatel" for product "Aos" and version " >= 6.1.5 < 6.1.5.595.r01" | - |
Affected
| in | Alcatel-lucent Search vendor "Alcatel-lucent" | Omniswitch Search vendor "Alcatel-lucent" for product "Omniswitch" | os6600 Search vendor "Alcatel-lucent" for product "Omniswitch" and version "os6600" | - |
Safe
|
Alcatel Search vendor "Alcatel" | Aos Search vendor "Alcatel" for product "Aos" | >= 6.1.5 < 6.1.5.595.r01 Search vendor "Alcatel" for product "Aos" and version " >= 6.1.5 < 6.1.5.595.r01" | - |
Affected
| in | Alcatel-lucent Search vendor "Alcatel-lucent" | Omniswitch Search vendor "Alcatel-lucent" for product "Omniswitch" | os6800 Search vendor "Alcatel-lucent" for product "Omniswitch" and version "os6800" | - |
Safe
|
Alcatel Search vendor "Alcatel" | Aos Search vendor "Alcatel" for product "Aos" | >= 6.1.5 < 6.1.5.595.r01 Search vendor "Alcatel" for product "Aos" and version " >= 6.1.5 < 6.1.5.595.r01" | - |
Affected
| in | Alcatel-lucent Search vendor "Alcatel-lucent" | Omniswitch Search vendor "Alcatel-lucent" for product "Omniswitch" | os6850 Search vendor "Alcatel-lucent" for product "Omniswitch" and version "os6850" | - |
Safe
|
Alcatel Search vendor "Alcatel" | Aos Search vendor "Alcatel" for product "Aos" | >= 6.1.5 < 6.1.5.595.r01 Search vendor "Alcatel" for product "Aos" and version " >= 6.1.5 < 6.1.5.595.r01" | - |
Affected
| in | Alcatel-lucent Search vendor "Alcatel-lucent" | Omniswitch Search vendor "Alcatel-lucent" for product "Omniswitch" | os7000 Search vendor "Alcatel-lucent" for product "Omniswitch" and version "os7000" | - |
Safe
|
Alcatel Search vendor "Alcatel" | Aos Search vendor "Alcatel" for product "Aos" | >= 6.1.5 < 6.1.5.595.r01 Search vendor "Alcatel" for product "Aos" and version " >= 6.1.5 < 6.1.5.595.r01" | - |
Affected
| in | Alcatel-lucent Search vendor "Alcatel-lucent" | Omniswitch Search vendor "Alcatel-lucent" for product "Omniswitch" | os9000 Search vendor "Alcatel-lucent" for product "Omniswitch" and version "os9000" | - |
Safe
|
Alcatel Search vendor "Alcatel" | Aos Search vendor "Alcatel" for product "Aos" | >= 6.3 < 6.3.1.966.r01 Search vendor "Alcatel" for product "Aos" and version " >= 6.3 < 6.3.1.966.r01" | - |
Affected
| in | Alcatel-lucent Search vendor "Alcatel-lucent" | Omniswitch Search vendor "Alcatel-lucent" for product "Omniswitch" | os6600 Search vendor "Alcatel-lucent" for product "Omniswitch" and version "os6600" | - |
Safe
|
Alcatel Search vendor "Alcatel" | Aos Search vendor "Alcatel" for product "Aos" | >= 6.3 < 6.3.1.966.r01 Search vendor "Alcatel" for product "Aos" and version " >= 6.3 < 6.3.1.966.r01" | - |
Affected
| in | Alcatel-lucent Search vendor "Alcatel-lucent" | Omniswitch Search vendor "Alcatel-lucent" for product "Omniswitch" | os6800 Search vendor "Alcatel-lucent" for product "Omniswitch" and version "os6800" | - |
Safe
|
Alcatel Search vendor "Alcatel" | Aos Search vendor "Alcatel" for product "Aos" | >= 6.3 < 6.3.1.966.r01 Search vendor "Alcatel" for product "Aos" and version " >= 6.3 < 6.3.1.966.r01" | - |
Affected
| in | Alcatel-lucent Search vendor "Alcatel-lucent" | Omniswitch Search vendor "Alcatel-lucent" for product "Omniswitch" | os6850 Search vendor "Alcatel-lucent" for product "Omniswitch" and version "os6850" | - |
Safe
|
Alcatel Search vendor "Alcatel" | Aos Search vendor "Alcatel" for product "Aos" | >= 6.3 < 6.3.1.966.r01 Search vendor "Alcatel" for product "Aos" and version " >= 6.3 < 6.3.1.966.r01" | - |
Affected
| in | Alcatel-lucent Search vendor "Alcatel-lucent" | Omniswitch Search vendor "Alcatel-lucent" for product "Omniswitch" | os7000 Search vendor "Alcatel-lucent" for product "Omniswitch" and version "os7000" | - |
Safe
|
Alcatel Search vendor "Alcatel" | Aos Search vendor "Alcatel" for product "Aos" | >= 6.3 < 6.3.1.966.r01 Search vendor "Alcatel" for product "Aos" and version " >= 6.3 < 6.3.1.966.r01" | - |
Affected
| in | Alcatel-lucent Search vendor "Alcatel-lucent" | Omniswitch Search vendor "Alcatel-lucent" for product "Omniswitch" | os9000 Search vendor "Alcatel-lucent" for product "Omniswitch" and version "os9000" | - |
Safe
|