CNCVE编号:CNCVE-20020040 CVE编号: 安全级别:高 漏洞中文描述: OmniPCX是企业级的Personal Communications Exchange (PCX)系统,由Alcatel负责维护开发。攻击者无须以halt、root用户登录,就以mtcl用户登录,执行/chetc/shutdown即可关机 漏洞英文描述: OmniPCX is an enterprise-level Personal Communications Exchange (PCX) system maintained and distributed by Alcatel. It is possible for any user with local access to the OmniPCX 4400 to shut down the system. This is due to the shutdown utility on the system being installed with a setuid root bit. While this is not inherently an issue, as OmniPCX systems are not designed for multi-user access, this problem may be compounded by the ability to access the system through one of the known default login and password combinations, as described in Bugtraq ID 4127 "Alcatel OmniPCX Default Passwords Vulnerability." 漏洞参考: http://archives.neohapsis.com/archives/bugtraq/2002-02/0188.html http://www.ind.alcatel.com/omnipcx/index.cfm?cnt=index 系统类型:其他 漏洞类型:设计错误