An issue was discovered in Alcatel-Lucent ALE NOE deskphones through 86x8_NOE-R300.1.40.12.4180 and SIP deskphones through 86x8_SIP-R200.1.01.10.728. Because of a time-of-check time-of-use vulnerability, an authenticated attacker is able to replace the verified firmware image with malicious firmware during the update process.
Metrics
Affected Vendors & Products
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
No history.
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-02T01:10:53.864Z
Reserved: 2024-03-18T00:00:00
Link: CVE-2024-29149
Updated: 2024-08-02T01:10:53.864Z
Status : Awaiting Analysis
Published: 2024-05-07T17:15:07.897
Modified: 2024-11-21T09:07:39.100
Link: CVE-2024-29149
No data.
OpenCVE Enrichment
No data.
Weaknesses