CVE-2015-2804: Alcatel-Lucent Omniswitch Firmware

Medium severity, CVSS 4.3. EPSS: 2% chance of exploitation in the next 30 days.

The management web interface in Alcatel-Lucent OmniSwitch 6450, 6250, 6850E, 9000E, 6400, and 6855 with firmware before 6.6.4.309.R01 and 6.6.5.x before 6.6.5.80.R02 generates weak session identifiers, which allows remote attackers to hijack arbitrary sessions via a brute force attack.

Affected products

  • Alcatel-Lucent Omniswitch Firmware: up to and including 6.4.5.r02; up to and including 6.4.6.r01; up to and including 6.6.4.r01; up to and including 6.6.5.r02

Published 2015-06-16. Last modified 2026-06-17.