Lucene search

K
cveMitreCVE-2010-3280
HistorySep 23, 2010 - 7:00 p.m.

CVE-2010-3280

2010-09-2319:00:14
CWE-200
mitre
web.nvd.nist.gov
22
cve-2010-3280
alcatel-lucent
omnitouch contact center
security vulnerability
remote attack

CVSS2

6.9

Attack Vector

ADJACENT_NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:A/AC:M/Au:N/C:C/I:P/A:P

AI Score

7

Confidence

Low

EPSS

0.013

Percentile

86.0%

The CCAgent option 9.0.8.4 and earlier in the management server (aka TSA) component in Alcatel-Lucent OmniTouch Contact Center Standard Edition relies on client-side authorization checking, and unconditionally sends the SuperUser password to the client for use during an authorized session, which allows remote attackers to monitor or reconfigure Contact Center operations via a modified client application.

Affected configurations

Nvd
Node
alcatel-lucentccagentRange8.0
OR
alcatel-lucentccagentMatch7.1
AND
alcatel-lucentomnitouch_contact_centerMatch--std
VendorProductVersionCPE
alcatel-lucentccagent*cpe:2.3:a:alcatel-lucent:ccagent:*:*:*:*:*:*:*:*
alcatel-lucentccagent7.1cpe:2.3:a:alcatel-lucent:ccagent:7.1:*:*:*:*:*:*:*
alcatel-lucentomnitouch_contact_center-cpe:2.3:a:alcatel-lucent:omnitouch_contact_center:-:-:std:*:*:*:*:*

CVSS2

6.9

Attack Vector

ADJACENT_NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:A/AC:M/Au:N/C:C/I:P/A:P

AI Score

7

Confidence

Low

EPSS

0.013

Percentile

86.0%

Related for CVE-2010-3280