5.1
CVE-2010-1910
- EPSS 1.1%
- Veröffentlicht 12.05.2010 11:46:31
- Zuletzt bearbeitet 11.04.2025 00:51:21
- Quelle cve@mitre.org
- CVE-Watchlists
- Unerledigt
The Forgot Password implementation in Consona Live Assistance, Dynamic Agent, and Subscriber Assistance allows remote attackers to reset passwords of accounts with blank Hint questions and Hint answers by sending an empty value for each of these two Hint fields.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Consona ≫ Consona Dynamic Agent Version- Update- Editionenterprise
Consona ≫ Consona Dynamic Agent Version- Update- Editionmarketing
Consona ≫ Consona Dynamic Agent Version- Update- Editionsupport
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 1.1% | 0.771 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 5.1 | 4.9 | 6.4 |
AV:N/AC:H/Au:N/C:P/I:P/A:P
|
CWE-287 Improper Authentication
When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.