An issue was discovered in Alcatel-Lucent ALE NOE deskphones through 86x8_NOE-R300.1.40.12.4180 and SIP deskphones through 86x8_SIP-R200.1.01.10.728. Because of a time-of-check time-of-use vulnerability, an authenticated attacker is able to replace the verified firmware image with malicious firmware during the update process.
Metrics
Affected Vendors & Products
References
History
Thu, 26 Feb 2026 13:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Alcatel-lucent
Alcatel-lucent ale 20 Alcatel-lucent ale 20h Alcatel-lucent ale 30 Alcatel-lucent ale 300 Alcatel-lucent ale 30h Alcatel-lucent ale 400 Alcatel-lucent ale 500 |
|
| CPEs | cpe:2.3:o:alcatel-lucent:ale_20:-:*:*:*:*:*:*:* cpe:2.3:o:alcatel-lucent:ale_20h:-:*:*:*:*:*:*:* cpe:2.3:o:alcatel-lucent:ale_300:-:*:*:*:*:*:*:* cpe:2.3:o:alcatel-lucent:ale_30:-:*:*:*:*:*:*:* cpe:2.3:o:alcatel-lucent:ale_30h:-:*:*:*:*:*:*:* cpe:2.3:o:alcatel-lucent:ale_400:-:*:*:*:*:*:*:* cpe:2.3:o:alcatel-lucent:ale_500:-:*:*:*:*:*:*:* |
|
| Vendors & Products |
Alcatel-lucent
Alcatel-lucent ale 20 Alcatel-lucent ale 20h Alcatel-lucent ale 30 Alcatel-lucent ale 300 Alcatel-lucent ale 30h Alcatel-lucent ale 400 Alcatel-lucent ale 500 |
|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-02T01:10:53.864Z
Reserved: 2024-03-18T00:00:00.000Z
Link: CVE-2024-29149
Updated: 2024-08-02T01:10:53.864Z
Status : Awaiting Analysis
Published: 2024-05-07T17:15:07.897
Modified: 2024-11-21T09:07:39.100
Link: CVE-2024-29149
No data.