Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2010-3280

EPSS 0.55% · P68
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2010-3280

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Description
The CCAgent option 9.0.8.4 and earlier in the management server (aka TSA) component in Alcatel-Lucent OmniTouch Contact Center Standard Edition relies on client-side authorization checking, and unconditionally sends the SuperUser password to the client for use during an authorized session, which allows remote attackers to monitor or reconfigure Contact Center operations via a modified client application.
Source: NVD (National Vulnerability Database)
CVSS Information
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Type
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Title
Alcatel-Lucent OmniTouch Contact Center安全绕过和信息泄露漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Alcatel-Lucent OmniTouch Contact Center Standard Edition中的management server (又名TSA)组件中的CCAgent选项9.0.8.4及更早版本在授权会话期间依靠客户端认证检查和无条件地发送SuperUser密码到客户端的使用。远程攻击者可以借助修改的客户端应用程序来监视或者重配置Contact Center的运行。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

VendorProductAffected VersionsCPESubscribe
-n/a n/a -

II. Public POCs for CVE-2010-3280

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2010-3280

Please Login to view more intelligence information

Same Patch Batch · n/a · 2010-09-23 · 12 CVEs total

CVE-2010-2828Cisco IOS 未明拒绝服务漏洞
CVE-2010-2829Cisco IOS未明漏洞
CVE-2010-2830Cisco IOS Internet Group Management Protocol拒绝服务漏洞
CVE-2010-2831Cisco IOS NAT Functionality Session Initiation Protocol拒绝服务攻击漏洞
CVE-2010-2832Cisco IOS NAT Functionality H.323拒绝服务攻击漏洞
CVE-2010-2833Cisco IOS NAT Functionality H.225.0拒绝服务攻击漏洞
CVE-2010-2834Cisco多个产品SIP未明拒绝服务攻击漏洞
CVE-2010-2835Cisco多个产品SIP REFER未明拒绝服务攻击漏洞
CVE-2010-2836Cisco IOS SSL VPN HTTP Redirect内存泄露远程拒绝服务攻击漏洞
CVE-2010-3279Alcatel-Lucent OmniTouch Contact Center安全绕过和拒绝服务攻击漏洞
CVE-2010-3281Alcatel-Lucent OmniVista 4760 HTTP Proxy远程缓冲区溢出漏洞

IV. Related Vulnerabilities

V. Comments for CVE-2010-3280

No comments yet


Leave a comment