← Vulnerability feed

Vulnerability record · CVE-2002-0295 · published 31 May 2002

CVE-2002-0295: Alcatel-lucent omnipcx vulnerability

AAlcatel Lucent · Omnipcx

Alcatel OmniPCX 4400 installs files with world-writable permissions, which allows local users to reconfigure the system and possibly gain privileges.

4.6 CVSS 2.0 Medium EPSS 0.31% · top 79.0%
4.6CVSS 2.0 base score
0.31%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
4References
16 Jun 2026Last modified by NVD

Description

Alcatel OmniPCX 4400 installs files with world-writable permissions, which allows local users to reconfigure the system and possibly gain privileges.

AV:L/AC:L/Au:N/C:P/I:P/A:P

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2002-0295 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2002-1691Alcatel-lucent omnipcx vulnerabilityAlcatel OmniPCX 4400 installs known user accounts and passwords in the /etc/password file by default, which allows remote attackers to gain unauthori…EPSS 3.6%8.5CVE-2007-5361Alcatel-lucent omnipcx vulnerabilityThe Communication Server in Alcatel-Lucent OmniPCX Enterprise 7.1 and earlier caches an IP address during a TFTP request from an IP Touch phone, and …EPSS 2.4%7.5CVE-2007-2512Alcatel-lucent omnipcx vulnerabilityAlcatel-Lucent IP-Touch Telephone running OmniPCX Enterprise 7.0 and later enables the mini switch by default, which allows attackers to gain access …EPSS 1.2%6.2CVE-2002-0293Alcatel-lucent omnipcx vulnerabilityFTP service in Alcatel OmniPCX 4400 allows the "halt" user to gain root privileges by modifying root's .profile file.EPSS 0.29%5.8CVE-2011-0344Alcatel-lucent omnipcx memory buffer overflow vulnerabilityMultiple stack-based buffer overflows in unspecified CGI programs in the Unified Maintenance Tool web interface in the embedded web server in the Com…EPSS 2.3%5.0CVE-2003-1108Alcatel-lucent omnipcx vulnerabilityThe Session Initiation Protocol (SIP) implementation in Alcatel OmniPCX Enterprise 5.0 Lx allows remote attackers to cause a denial of service and po…EPSS 5.0%2.1CVE-2002-0294Alcatel-lucent omnipcx vulnerabilityAlcatel 4400 installs the /chetc/shutdown command with setgid privileges, which allows many different local users to shut down the system.EPSS 0.29%

Source: NIST National Vulnerability Database (record CVE-2002-0295), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.