NVD
- Id
- 14693
- Name
- CVE-2010-3280
- Description
- The CCAgent option 9.0.8.4 and earlier in the management server (aka TSA) component in Alcatel-Lucent OmniTouch Contact Center Standard Edition relies on client-side authorization checking, and unconditionally sends the SuperUser password to the client for use during an authorized session, which allows remote attackers to monitor or reconfigure Contact Center operations via a modified client application.
- Reject
- CVSS Version
- 2
- CVSS Score
- 6.9
- Severity
- Medium
- CVSS Base Score
- 6.9
- CVSS Impact Subscore
- 8.5
- CVSS Exploit Subscore
- 5.5
- CVSS Vector
- (AV:A/AC:M/Au:N/C:C/I:P/A:P)
- Pub Date
- 2017-01-18
- Published
- 2010-09-23
- Modified Date
- 2010-09-24
- Seq
- 2010-3280