← Vulnerability feed

Vulnerability record · CVE-2003-1108 · published 31 December 2003

CVE-2003-1108: Alcatel-lucent omnipcx vulnerability

AAlcatel Lucent · Omnipcx

The Session Initiation Protocol (SIP) implementation in Alcatel OmniPCX Enterprise 5.0 Lx allows remote attackers to cause a denial of service and possibly execute arbitrary code via crafted INVITE messages, as demonstrated by the OUSPG PROTOS c07-sip test suite.

5.0 CVSS 2.0 Medium EPSS 5.0% · top 8.1%
5.0CVSS 2.0 base score
5.0%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
12References, 2 tagged exploit
16 Jun 2026Last modified by NVD

Description

The Session Initiation Protocol (SIP) implementation in Alcatel OmniPCX Enterprise 5.0 Lx allows remote attackers to cause a denial of service and possibly execute arbitrary code via crafted INVITE messages, as demonstrated by the OUSPG PROTOS c07-sip test suite.

AV:N/AC:L/Au:N/C:N/I:N/A:P

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2003-1108 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2002-1691Alcatel-lucent omnipcx vulnerabilityAlcatel OmniPCX 4400 installs known user accounts and passwords in the /etc/password file by default, which allows remote attackers to gain unauthori…EPSS 3.6%8.5CVE-2007-5361Alcatel-lucent omnipcx vulnerabilityThe Communication Server in Alcatel-Lucent OmniPCX Enterprise 7.1 and earlier caches an IP address during a TFTP request from an IP Touch phone, and …EPSS 2.4%7.5CVE-2007-2512Alcatel-lucent omnipcx vulnerabilityAlcatel-Lucent IP-Touch Telephone running OmniPCX Enterprise 7.0 and later enables the mini switch by default, which allows attackers to gain access …EPSS 1.2%6.2CVE-2002-0293Alcatel-lucent omnipcx vulnerabilityFTP service in Alcatel OmniPCX 4400 allows the "halt" user to gain root privileges by modifying root's .profile file.EPSS 0.29%5.8CVE-2011-0344Alcatel-lucent omnipcx memory buffer overflow vulnerabilityMultiple stack-based buffer overflows in unspecified CGI programs in the Unified Maintenance Tool web interface in the embedded web server in the Com…EPSS 2.3%4.6CVE-2002-0295Alcatel-lucent omnipcx vulnerabilityAlcatel OmniPCX 4400 installs files with world-writable permissions, which allows local users to reconfigure the system and possibly gain privileges.EPSS 0.31%2.1CVE-2002-0294Alcatel-lucent omnipcx vulnerabilityAlcatel 4400 installs the /chetc/shutdown command with setgid privileges, which allows many different local users to shut down the system.EPSS 0.29%

Source: NIST National Vulnerability Database (record CVE-2003-1108), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.