Vulnerability CVE-2010-1910


Published: 2010-05-12   Modified: 2012-02-13

Description:
The Forgot Password implementation in Consona Live Assistance, Dynamic Agent, and Subscriber Assistance allows remote attackers to reset passwords of accounts with blank Hint questions and Hint answers by sending an empty value for each of these two Hint fields.

See advisories in our WLB2 database:
Topic
Author
Date
High
Consona Products - Multiple vulnerabilities
wintercore
23.05.2010
Med.
Consona Password Reset Security Bypass
Rafael Pedrero
26.11.2018

Type:

CWE-287

(Improper Authentication)

CVSS2 => (AV:N/AC:H/Au:N/C:P/I:P/A:P)

CVSS Base Score
Impact Subscore
Exploitability Subscore
5.1/10
6.4/10
4.9/10
Exploit range
Attack complexity
Authentication
Remote
High
No required
Confidentiality impact
Integrity impact
Availability impact
Partial
Partial
Partial
Affected software
Consona -> Consona dynamic agent 
Consona -> Consona live assistance 
Consona -> Consona subscriber assistance 

 References:
http://wintercore.com/en/component/content/article/7-media/18-wintercore-releases-an-advisory-for-consona-products.html
http://www.consona.com/Content/CRM/Support/SecurityBulletin_April2010.pdf
http://www.kb.cert.org/vuls/id/602801
http://www.securityfocus.com/archive/1/511176/100/0/threaded
http://www.securityfocus.com/bid/40003

Copyright 2024, cxsecurity.com

 

Back to Top