VRDA Feed by JPCERT/CC
  Vulnerability Response Decision Assistance Feed : Information for vulnerability impact analysis
[ about VRDA Feed | JPCERT/CC



 
Vulnerability Analysis Result (Revision No : 1) [ Download XML
CVE-2010-1913
consona_dynamic_agent, consona_live_assistance, consona_subscriber_assistance: The default configuration of pluginlicense.ini for ...
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2010-1913

Original

The default configuration of pluginlicense.ini for the SdcWebSecureBase interface in tgctlcm.dll in Consona Live Assistance, Dynamic Agent, and Subscriber Assistance, when downloaded from a server operated by Telefonica or possibly other companies, contains an incorrect DNS whitelist that includes the DNS hostnames of home computers of many persons, which allows remote attackers to bypass intended restrictions on ActiveX execution by hosting an ActiveX control on an applicable home web server.

Translation   (Show)





About This Analysis Information
Analysis Information Provider:
NIST NVD
First Published:
2010-05-12
Source Information Category:
Advisory, Alert
Last Updated:
2010-05-12




Affected Product Tags
cpe:/a:consona:consona_dynamic_agent:-:-:enterprise
cpe:/a:consona:consona_dynamic_agent:-:-:marketing
cpe:/a:consona:consona_dynamic_agent:-:-:support
cpe:/a:consona:consona_live_assistance
cpe:/a:consona:consona_subscriber_assistance
 


Vulnerability Analysis Results
[Access Vector]  [?]
Undefined [?]

Local [?]
Adjacent Network [?]
X Network [?]

[Access Complexit]  [?]
Undefined [?]

High [?]
X Medium [?]
Low [?]

[Authentication]  [?]
Undefined [?]

Multiple [?]
Single [?]
X None [?]

[Confidentiality Impact]  [?]
Undefined [?]

None [?]
Partial [?]
X Complete [?]

[Integrity Impact]  [?]
Undefined [?]

None [?]
Partial [?]
X Complete [?]

[Availability Impact]  [?]
Undefined [?]

None [?]
Partial [?]
X Complete [?]

Alternatives




References
VU#602801




BUGTRAQ 20100507 [Wintercore Research] Consona Products - Multiple vulnerabilities




MISC http://www.wintercore.com/downloads/rootedcon_0day.pdf




MISC http://wintercore.com/en/component/content/article/7-media/18-wintercore-releases-an-advisory-for-consona-products.html




Vulnerability Type Configuration (CWE-16)





Copyright © 2010 JPCERT/CC All Rights Reserved.