CVE-2010-3280: Infoleak
The CCAgent option 9.0.8.4 and earlier in the management server (aka TSA) component in Alcatel-Lucent OmniTouch Contact Center Standard Edition relies on client-side authorization checking, and unconditionally sends the SuperUser password to the client for use during an authorized session, which allows remote attackers to monitor or reconfigure Contact Center operations via a modified client application.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2010-3280?
CVE-2010-3280 is considered a critical vulnerability due to its potential for unauthorized access to sensitive credentials.
How do I fix CVE-2010-3280?
To mitigate CVE-2010-3280, upgrade to a version of CCAgent that addresses this vulnerability beyond 9.0.8.4.
What systems are affected by CVE-2010-3280?
CVE-2010-3280 affects Alcatel-Lucent CCAgent versions 8.0 and earlier, as well as OmniTouch Contact Center Standard Edition.
Is client-side authorization secure in CVE-2010-3280?
No, client-side authorization is not secure in CVE-2010-3280 as it relies on insufficient checks leading to exposure of credentials.
What impact does CVE-2010-3280 have on users?
CVE-2010-3280 can lead to unauthorized users gaining access to SuperUser permissions, potentially compromising the system.