CVE Vulnerabilities

CVE-2010-1911

Published: May 12, 2010 | Modified: Oct 10, 2018
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
9.3 HIGH
AV:N/AC:M/Au:N/C:C/I:C/A:C
RedHat/V2
RedHat/V3
Ubuntu

The site-locking implementation in the SdcWebSecureBase interface in tgctlcm.dll in Consona Live Assistance, Dynamic Agent, and Subscriber Assistance relies on a list of server domain names to restrict execution of ActiveX controls, which makes it easier for man-in-the-middle attackers to execute arbitrary code via a DNS hijacking attack.

Affected Software

Name Vendor Start Version End Version
Consona_dynamic_agent Consona - (including) - (including)
Consona_live_assistance Consona * *
Consona_subscriber_assistance Consona * *

References