« Volver al listado

CVE-2010-1907

Estado: ModificadaMedia (4.3)—

The SdcUser.TgConCtl ActiveX control in tgctlcm.dll in Consona Live Assistance, Dynamic Agent, and Subscriber Assistance allows remote attackers to discover the username of the client user, and consequently determine a pathname to a certain user directory, via a call to the GetUserName method.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (3)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2010-1907",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 4.3,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:M/Au:N/C:P/I:N/A:N",
          "authentication": "NONE",
          "integrityImpact": "NONE",
          "accessComplexity": "MEDIUM",
          "availabilityImpact": "NONE",
          "confidentialityImpact": "PARTIAL"
        },
        "acInsufInfo": false,
        "impactScore": 2.9,
        "baseSeverity": "MEDIUM",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 8.6,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": true
      }
    ]
  },
  "affected": [
    {
      "source": "cve@mitre.org",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "n/a",
          "versions": [
            {
              "status": "affected",
              "version": "n/a"
            }
          ]
        }
      ]
    }
  ],
  "published": "2010-05-12T11:46:31.610",
  "references": [
    {
      "url": "http://wintercore.com/en/component/content/article/7-media/18-wintercore-releases-an-advisory-for-consona-products.html",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.kb.cert.org/vuls/id/602801",
      "tags": [
        "Patch",
        "US Government Resource"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.securityfocus.com/archive/1/511176/100/0/threaded",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.wintercore.com/downloads/rootedcon_0day.pdf",
      "tags": [
        "Exploit"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "http://wintercore.com/en/component/content/article/7-media/18-wintercore-releases-an-advisory-for-consona-products.html",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.kb.cert.org/vuls/id/602801",
      "tags": [
        "Patch",
        "US Government Resource"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.securityfocus.com/archive/1/511176/100/0/threaded",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.wintercore.com/downloads/rootedcon_0day.pdf",
      "tags": [
        "Exploit"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-200"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "The SdcUser.TgConCtl ActiveX control in tgctlcm.dll in Consona Live Assistance, Dynamic Agent, and Subscriber Assistance allows remote attackers to discover the username of the client user, and consequently determine a pathname to a certain user directory, via a call to the GetUserName method."
    },
    {
      "lang": "es",
      "value": "El control ActiveX SdcUser.TgConCtl en tgctlcm.dll en Consona Live Assistance, Dynamic Agent, y Subscriber Assistance permite a atacantes remotos descubrir el nombre de usuario del usuario cliente, y en consecuencia determinar la ruta de acceso a un directorio de usuario determinado , a través de una llamada al método GetUserName.\r\n\r\n"
    }
  ],
  "lastModified": "2026-06-16T23:19:34.000",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:consona:consona_dynamic_agent:-:-:enterprise:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "3E86DC4D-1E5C-4284-AA49-FD5F3AA9056A"
            },
            {
              "criteria": "cpe:2.3:a:consona:consona_dynamic_agent:-:-:marketing:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "76A93E2B-D458-43A4-A4A5-9FA0981B72EF"
            },
            {
              "criteria": "cpe:2.3:a:consona:consona_dynamic_agent:-:-:support:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "F1AAF4CD-3D1A-4C44-8338-4F614E4645CB"
            },
            {
              "criteria": "cpe:2.3:a:consona:consona_live_assistance:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "EDD3CC62-BB8B-435F-A9F3-CD6DE608F463"
            },
            {
              "criteria": "cpe:2.3:a:consona:consona_subscriber_assistance:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "1F445B64-34D5-4372-9861-2216442E4069"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "cve@mitre.org"
}