CVE-2010-3280 - CERT CVE
ID CVE-2010-3280
Sažetak The CCAgent option 9.0.8.4 and earlier in the management server (aka TSA) component in Alcatel-Lucent OmniTouch Contact Center Standard Edition relies on client-side authorization checking, and unconditionally sends the SuperUser password to the client for use during an authorized session, which allows remote attackers to monitor or reconfigure Contact Center operations via a modified client application.
Reference
CVSS
Base: 6.9
Impact: 8.5
Exploitability:5.5
Pristup
VektorSloženostAutentikacija
ADJACENT_NETWORK MEDIUM NONE
Impact
PovjerljivostCjelovitostDostupnost
COMPLETE PARTIAL PARTIAL
CVSS vektor AV:A/AC:M/Au:N/C:C/I:P/A:P
Zadnje važnije ažuriranje 17-08-2017 - 01:32
Objavljeno 23-09-2010 - 19:00