CVE-2010-3280

Published Sep 23, 2010

Last updated 7 years ago

Overview

Description
The CCAgent option 9.0.8.4 and earlier in the management server (aka TSA) component in Alcatel-Lucent OmniTouch Contact Center Standard Edition relies on client-side authorization checking, and unconditionally sends the SuperUser password to the client for use during an authorized session, which allows remote attackers to monitor or reconfigure Contact Center operations via a modified client application.
Source
cve@mitre.org
NVD status
Modified

Social media

Hype score
Not currently trending

Risk scores

CVSS 2.0

Type
Primary
Base score
6.9
Impact score
8.5
Exploitability score
5.5
Vector string
AV:A/AC:M/Au:N/C:C/I:P/A:P

Weaknesses

nvd@nist.gov
CWE-200

Configurations