VRDA Feed by JPCERT/CC
  Vulnerability Response Decision Assistance Feed : Information for vulnerability impact analysis
[ about VRDA Feed | JPCERT/CC



 
Vulnerability Analysis Result (Revision No : 1) [ Download XML
CVE-2010-1910
consona_dynamic_agent, consona_live_assistance, consona_subscriber_assistance: The Forgot Password implementation in Consona Live ...
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2010-1910

Original

The Forgot Password implementation in Consona Live Assistance, Dynamic Agent, and Subscriber Assistance allows remote attackers to reset passwords of accounts with blank Hint questions and Hint answers by sending an empty value for each of these two Hint fields.

Translation   (Show)





About This Analysis Information
Analysis Information Provider:
NIST NVD
First Published:
2010-05-12
Source Information Category:
Advisory, Alert
Last Updated:
2010-05-12




Affected Product Tags
cpe:/a:consona:consona_dynamic_agent:-:-:enterprise
cpe:/a:consona:consona_dynamic_agent:-:-:marketing
cpe:/a:consona:consona_dynamic_agent:-:-:support
cpe:/a:consona:consona_live_assistance
cpe:/a:consona:consona_subscriber_assistance
 


Vulnerability Analysis Results
[Access Vector]  [?]
Undefined [?]

Local [?]
Adjacent Network [?]
X Network [?]

[Access Complexit]  [?]
Undefined [?]

X High [?]
Medium [?]
Low [?]

[Authentication]  [?]
Undefined [?]

Multiple [?]
Single [?]
X None [?]

[Confidentiality Impact]  [?]
Undefined [?]

None [?]
X Partial [?]
Complete [?]

[Integrity Impact]  [?]
Undefined [?]

None [?]
X Partial [?]
Complete [?]

[Availability Impact]  [?]
Undefined [?]

None [?]
X Partial [?]
Complete [?]

Alternatives




References
VU#602801




BID 40003




BUGTRAQ 20100507 [Wintercore Research] Consona Products - Multiple vulnerabilities




CONFIRM http://www.consona.com/Content/CRM/Support/SecurityBulletin_April2010.pdf




MISC http://wintercore.com/en/component/content/article/7-media/18-wintercore-releases-an-advisory-for-consona-products.html




SECUNIA 39740




Vulnerability Type Authentication Issues (CWE-287)





Copyright © 2010 JPCERT/CC All Rights Reserved.