Vulnerability Details CVE-2008-4383
Stack-based buffer overflow in the Agranet-Emweb embedded management web server in Alcatel OmniSwitch OS7000, OS6600, OS6800, OS6850, and OS9000 Series devices with AoS 5.1 before 5.1.6.463.R02, 5.4 before 5.4.1.429.R01, 6.1.3 before 6.1.3.965.R01, 6.1.5 before 6.1.5.595.R01, and 6.3 before 6.3.1.966.R01 allows remote attackers to execute arbitrary code via a long Session cookie.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.271
EPSS Ranking 96.1%
CVSS Severity
CVSS v2 Score 10.0
Products affected by CVE-2008-4383
-
cpe:2.3:h:alcatel-lucent:omniswitch:os6600
-
cpe:2.3:h:alcatel-lucent:omniswitch:os6800
-
cpe:2.3:h:alcatel-lucent:omniswitch:os6850
-
cpe:2.3:h:alcatel-lucent:omniswitch:os7000
-
cpe:2.3:h:alcatel-lucent:omniswitch:os9000
-
-
cpe:2.3:o:alcatel:aos:5.1.1
-
cpe:2.3:o:alcatel:aos:5.1.6.463
-
cpe:2.3:o:alcatel:aos:5.4.1.429
-
cpe:2.3:o:alcatel:aos:6.1.3.965
-
cpe:2.3:o:alcatel:aos:6.3.1.966