Lucene search

K
cveMitreCVE-2010-3279
HistorySep 23, 2010 - 7:00 p.m.

CVE-2010-3279

2010-09-2319:00:14
CWE-16
mitre
web.nvd.nist.gov
24
cve-2010-3279
ccagent
alcatel-lucent
omnitouch
contact center
management server
tsa
maintenance access
remote attackers
monitor
reconfigure operations

CVSS2

7.6

Attack Vector

ADJACENT_NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

PARTIAL

Availability Impact

COMPLETE

AV:A/AC:M/Au:N/C:C/I:P/A:C

AI Score

6.7

Confidence

Low

EPSS

0.018

Percentile

88.2%

The default configuration of the CCAgent option before 9.0.8.4 in the management server (aka TSA) component in Alcatel-Lucent OmniTouch Contact Center Standard Edition enables maintenance access, which allows remote attackers to monitor or reconfigure Contact Center operations via vectors involving TSA_maintenance.exe.

Affected configurations

Nvd
Node
alcatel-lucentccagentRange8.0
OR
alcatel-lucentccagentMatch7.1
AND
alcatel-lucentomnitouch_contact_centerMatch--std
VendorProductVersionCPE
alcatel-lucentccagent*cpe:2.3:a:alcatel-lucent:ccagent:*:*:*:*:*:*:*:*
alcatel-lucentccagent7.1cpe:2.3:a:alcatel-lucent:ccagent:7.1:*:*:*:*:*:*:*
alcatel-lucentomnitouch_contact_center-cpe:2.3:a:alcatel-lucent:omnitouch_contact_center:-:-:std:*:*:*:*:*

CVSS2

7.6

Attack Vector

ADJACENT_NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

PARTIAL

Availability Impact

COMPLETE

AV:A/AC:M/Au:N/C:C/I:P/A:C

AI Score

6.7

Confidence

Low

EPSS

0.018

Percentile

88.2%

Related for CVE-2010-3279