Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-8r4h-25v6-93q9

Опубликовано: 17 мая 2022
Источник: github
Github: Не прошло ревью

Описание

The CCAgent option 9.0.8.4 and earlier in the management server (aka TSA) component in Alcatel-Lucent OmniTouch Contact Center Standard Edition relies on client-side authorization checking, and unconditionally sends the SuperUser password to the client for use during an authorized session, which allows remote attackers to monitor or reconfigure Contact Center operations via a modified client application.

The CCAgent option 9.0.8.4 and earlier in the management server (aka TSA) component in Alcatel-Lucent OmniTouch Contact Center Standard Edition relies on client-side authorization checking, and unconditionally sends the SuperUser password to the client for use during an authorized session, which allows remote attackers to monitor or reconfigure Contact Center operations via a modified client application.

EPSS

Процентиль: 67%
0.00549
Низкий

Дефекты

CWE-200

Связанные уязвимости

nvd
больше 15 лет назад

The CCAgent option 9.0.8.4 and earlier in the management server (aka TSA) component in Alcatel-Lucent OmniTouch Contact Center Standard Edition relies on client-side authorization checking, and unconditionally sends the SuperUser password to the client for use during an authorized session, which allows remote attackers to monitor or reconfigure Contact Center operations via a modified client application.

EPSS

Процентиль: 67%
0.00549
Низкий

Дефекты

CWE-200