EXPOSURES › CVE-2007-3010
CVE-2007-3010
HIGH ⌖ ON CISA KEV · EXPLOITEDAlcatel OmniPCX Enterprise's masterCGI in the Unified Maintenance Tool allows remote attackers to execute arbitrary commands.
This remote code execution vulnerability in Alcatel's OmniPCX Enterprise Communication Server enables attackers to run arbitrary commands remotely, posing a severe risk to DIB organizations relying on this telephony infrastructure. The flaw is actively exploited in the wild and linked to ransomware campaigns, meaning unpatched systems are likely already compromised. DIB orgs must immediately patch this CVE and assess their exposure, as the combination of RCE and active exploitation represents a critical compliance and operational failure.
Shame score — The vendor shipped a product with a known RCE flaw that is actively exploited in the wild, indicating a severe failure in patch management and security hygiene that directly enables ransomware attacks.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
masterCGI in the Unified Maintenance Tool in Alcatel OmniPCX Enterprise Communication Server allows remote attackers to execute arbitrary commands.