CVE Vulnerabilities

CVE-2010-1910

Improper Authentication

Published: May 12, 2010 | Modified: Oct 10, 2018
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
5.1 MEDIUM
AV:N/AC:H/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu

The Forgot Password implementation in Consona Live Assistance, Dynamic Agent, and Subscriber Assistance allows remote attackers to reset passwords of accounts with blank Hint questions and Hint answers by sending an empty value for each of these two Hint fields.

Weakness

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

Affected Software

Name Vendor Start Version End Version
Consona_dynamic_agent Consona - -
Consona_subscriber_assistance Consona * *
Consona_dynamic_agent Consona - -
Consona_live_assistance Consona * *
Consona_dynamic_agent Consona - -

Potential Mitigations

References