Vulnerability Description
The default configuration of pluginlicense.ini for the SdcWebSecureBase interface in tgctlcm.dll in Consona Live Assistance, Dynamic Agent, and Subscriber Assistance, when downloaded from a server operated by Telefonica or possibly other companies, contains an incorrect DNS whitelist that includes the DNS hostnames of home computers of many persons, which allows remote attackers to bypass intended restrictions on ActiveX execution by hosting an ActiveX control on an applicable home web server.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Consona | Consona Dynamic Agent | - |
| Consona | Consona Live Assistance | All versions |
| Consona | Consona Subscriber Assistance | All versions |
Related Weaknesses (CWE)
References
- http://wintercore.com/en/component/content/article/7-media/18-wintercore-release
- http://www.kb.cert.org/vuls/id/602801PatchUS Government Resource
- http://www.securityfocus.com/archive/1/511176/100/0/threaded
- http://www.wintercore.com/downloads/rootedcon_0day.pdfExploit
- http://wintercore.com/en/component/content/article/7-media/18-wintercore-release
- http://www.kb.cert.org/vuls/id/602801PatchUS Government Resource
- http://www.securityfocus.com/archive/1/511176/100/0/threaded
- http://www.wintercore.com/downloads/rootedcon_0day.pdfExploit
FAQ
What is CVE-2010-1913?
CVE-2010-1913 is a vulnerability with a CVSS score of 9.3 (HIGH). The default configuration of pluginlicense.ini for the SdcWebSecureBase interface in tgctlcm.dll in Consona Live Assistance, Dynamic Agent, and Subscriber Assistance, when downloaded from a server ope...
How severe is CVE-2010-1913?
CVE-2010-1913 has been rated HIGH with a CVSS base score of 9.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2010-1913?
Check the references section above for vendor advisories and patch information. Affected products include: Consona Consona Dynamic Agent, Consona Consona Live Assistance, Consona Consona Subscriber Assistance.