
DescriptionAn issue was discovered in Alcatel-Lucent ALE NOE deskphones through 86x8_NOE-R300. and SIP deskphones through 86x8_SIP-R200. Because of a time-of-check time-of-use vulnerability, an authenticated attacker is able to replace the verified firmware image with malicious firmware during the update process.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)


NOT-FOR-US: Alcatel-Lucent ALE NOE deskphones

