CVE-2016-9796
Description
Alcatel-Lucent OmniVista 8770 2.0 through 3.0 exposes different ORBs interfaces, which can be queried using the GIOP protocol on TCP port 30024. An attacker can bypass authentication, and OmniVista invokes methods (AddJobSet, AddJob, and ExecuteNow) that can be used to run arbitrary commands on the server, with the privilege of NT AUTHORITY\SYSTEM on the server. NOTE: The discoverer states "The vendor position is to refer to the technical guidelines of the product security deployment to mitigate this issue, which means applying proper firewall rules to prevent unauthorised clients to connect to the OmniVista server."
In plain language
AI Worth attentionOmniVista 8770 Network Management System versions 2.0 through 3.0 can let a network-connected attacker take full control without logging in, so restrict access to port 30024 now.
Unauthenticated network RCE via exposed GIOP/ORB interfaces on TCP port 30024 allows execution of operating-system commands with full administrative privileges.
What to do now
- Check whether you run OmniVista 8770 Network Management System and whether TCP port 30024 is reachable from untrusted networks.
- There is no confirmed fixed version available; ask your Alcatel-Lucent/Nokia support contact for the supported remediation path.
- Block inbound TCP port 30024 at firewalls except from specifically approved management systems.
- Review the server for unexpected administrator-level commands, jobs, or configuration changes.
CVSS Vector Breakdown
AV:NAttack VectorAC:LAttack ComplexityPR:NPrivileges RequiredUI:NUser InteractionS:UScopeC:HConfidentialityI:HIntegrityA:HAvailabilityWeaknesses
Affected Products
Exploitability
Exploit details including PoC links, Metasploit modules, and scanner templates are available after registration.
View exploit detailsAttack Graph
Click technique nodes for MITRE ATT&CK details · drag to pan · Ctrl/⌘ + scroll to zoom, or go fullscreen.
MITRE ATT&CK
2 techniquesReferences
Unlock Complete Vulnerability Intelligence
Get the full picture for CVE-2016-9796 and every CVE in our database. Create a free account — no credit card required.
Create Free Account