VRDA Feed by JPCERT/CC
  Vulnerability Response Decision Assistance Feed : Information for vulnerability impact analysis
[ about VRDA Feed | JPCERT/CC



 
Vulnerability Analysis Result (Revision No : 1) [ Download XML
CVE-2010-1906
consona_dynamic_agent, consona_repair_manager, consona_subscriber_activation, con...: tgsrv.exe in the Repair Service in Consona Dynamic ...
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2010-1906

Original

tgsrv.exe in the Repair Service in Consona Dynamic Agent, Repair Manager, Subscriber Activation, and Subscriber Agent relies on a predictable timestamp field to validate input to the \\.\pipe\__RepairService_pipe__company named pipe, which allows remote authenticated users to execute arbitrary code by obtaining the current time from (1) tcpip.sys or (2) an SMB2 service.

Translation   (Show)





About This Analysis Information
Analysis Information Provider:
NIST NVD
First Published:
2010-05-12
Source Information Category:
Advisory, Alert
Last Updated:
2010-05-12




Affected Product Tags
cpe:/a:consona:consona_dynamic_agent:-:-:enterprise
cpe:/a:consona:consona_dynamic_agent:-:-:marketing
cpe:/a:consona:consona_dynamic_agent:-:-:support
cpe:/a:consona:consona_repair_manager
cpe:/a:consona:consona_subscriber_activation
cpe:/a:consona:consona_subscriber_agent
cpe:/o:microsoft:windows_7
cpe:/o:microsoft:windows_vista
 


Vulnerability Analysis Results
[Access Vector]  [?]
Undefined [?]

X Local [?]
Adjacent Network [?]
Network [?]

[Access Complexit]  [?]
Undefined [?]

High [?]
Medium [?]
X Low [?]

[Authentication]  [?]
Undefined [?]

Multiple [?]
Single [?]
X None [?]

[Confidentiality Impact]  [?]
Undefined [?]

None [?]
Partial [?]
X Complete [?]

[Integrity Impact]  [?]
Undefined [?]

None [?]
Partial [?]
X Complete [?]

[Availability Impact]  [?]
Undefined [?]

None [?]
Partial [?]
X Complete [?]

Alternatives




References
VU#602801




BUGTRAQ 20100507 [Wintercore Research] Consona Products - Multiple vulnerabilities




CONFIRM http://www.consona.com/Content/CRM/Support/SecurityBulletin_April2010.pdf




MISC http://www.wintercore.com/downloads/rootedcon_0day.pdf




MISC http://wintercore.com/en/component/content/article/7-media/18-wintercore-releases-an-advisory-for-consona-products.html




SECUNIA 39752




Vulnerability Type Cryptographic Issues (CWE-310)





Copyright © 2010 JPCERT/CC All Rights Reserved.