Alcatel Lucent's vulnerability footprint concentrates in a focused set of enterprise telecommunications and networking products, including voice and call-management systems such as OmniPCX and OmniSwitch switching infrastructure, that serve as critical infrastructure in carrier and large-enterprise deployments. The disclosures span a modest volume relative to the vendor's age and installed base, reflecting the specialized and often isolated network role these products occupy rather than broad consumer or cloud exposure. Defenders managing these telecommunications platforms should maintain awareness of this vendor's advisories and coordinate patching carefully within their network architecture, as the products involved typically sit in privileged network positions. Current exploitation activity, severity distribution, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Alcatel Lucent over time
Signals from CVEs in this vendor scope (26 CVEs).
26 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2016-9796CRITICAL Alcatel-Lucent OmniVista 8770 2.0 through 3.0 exposes different ORBs interfaces, which can be queried using the GIOP protocol on TCP port 30024. An attacker can bypass authenticati | Dec 3, 2016 | 9.8 | 41 | NO | YES |
CVE-2008-1331HIGH cgi-data/FastJSData.cgi in OmniPCX Office with Internet Access services OXO210 before 210/091.001, OXO600 before 610/014.001, and other versions, allows remote attackers to execute | Apr 2, 2008 | 10.0 | 38 | NO | YES |
CVE-2008-4383HIGH Stack-based buffer overflow in the Agranet-Emweb embedded management web server in Alcatel OmniSwitch OS7000, OS6600, OS6800, OS6850, and OS9000 Series devices with AoS 5.1 before | Oct 3, 2008 | 10.0 | 30 | NO | NO |
CVE-2007-1822HIGH Alcatel-Lucent Lucent Technologies voice mail systems allow remote attackers to retrieve or remove messages, or reconfigure mailboxes, by spoofing Calling Number Identification (CN | Apr 2, 2007 | 10.0 | 28 | NO | NO |
CVE-2002-1691HIGH Alcatel OmniPCX 4400 installs known user accounts and passwords in the /etc/password file by default, which allows remote attackers to gain unauthorized access. | Dec 31, 2002 | 10.0 | 28 | NO | NO |
CVE-2015-2805MEDIUM Cross-site request forgery (CSRF) vulnerability in sec/content/sec_asa_users_local_db_add.html in the management web interface in Alcatel-Lucent OmniSwitch 6450, 6250, 6850E, 9000E | Jun 16, 2015 | 6.8 | 27 | NO | YES |
CVE-2010-3279HIGH The default configuration of the CCAgent option before 9.0.8.4 in the management server (aka TSA) component in Alcatel-Lucent OmniTouch Contact Center Standard Edition enables main | Sep 23, 2010 | 7.6 | 23 | NO | NO |
CVE-2007-5361HIGH The Communication Server in Alcatel-Lucent OmniPCX Enterprise 7.1 and earlier caches an IP address during a TFTP request from an IP Touch phone, and uses this IP address as the des | Nov 20, 2007 | 8.5 | 23 | NO | NO |
CVE-2010-3280MEDIUM The CCAgent option 9.0.8.4 and earlier in the management server (aka TSA) component in Alcatel-Lucent OmniTouch Contact Center Standard Edition relies on client-side authorization | Sep 23, 2010 | 6.9 | 22 | NO | NO |
CVE-2007-5190MEDIUM Multiple cross-site scripting (XSS) vulnerabilities in Alcatel OmniVista 4760 R4.2 and earlier allow remote attackers to inject arbitrary web script or HTML via (1) the action para | Oct 22, 2007 | 4.3 | 21 | NO | YES |
Signals from CVEs in this vendor scope (26 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Alcatel Lucent.
Media articles that mention a CVE ID that affects a product developed by Alcatel Lucent — matched by CVE ID, not by vendor name.