First published: Thu Sep 23 2010(Updated: )
The default configuration of the CCAgent option before 9.0.8.4 in the management server (aka TSA) component in Alcatel-Lucent OmniTouch Contact Center Standard Edition enables maintenance access, which allows remote attackers to monitor or reconfigure Contact Center operations via vectors involving TSA_maintenance.exe.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Alcatel-Lucent CCagent | <=8.0 | |
Alcatel-Lucent CCagent | =7.1 | |
Alcatel-Lucent OmniTouch Contact Center |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2010-3279 is categorized as a medium severity vulnerability that allows unauthorized maintenance access.
To fix CVE-2010-3279, update to version 9.0.8.4 or later of the CCAgent option to disable the default maintenance access.
CVE-2010-3279 affects Alcatel-Lucent CCAgent versions prior to 9.0.8.4 and the OmniTouch Contact Center Standard Edition.
The risks of CVE-2010-3279 include allowing remote attackers to monitor or reconfigure critical Contact Center operations.
While CVE-2010-3279 is an older vulnerability, systems still running vulnerable versions can remain at risk if not updated.