SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2010-1907

The SdcUser.TgConCtl ActiveX control in tgctlcm.dll in Consona Live Assistance, Dynamic Agent, and Subscriber Assistance allows remote attackers to discover the username of the client user, and consequently determine a pathname to a certain user…

MEDIUM 4.3EPSS 1.53%

Does this matter?

Lower severity and a low EPSS score (1.53%). Track it; it rarely justifies an emergency change on its own.

Description

The SdcUser.TgConCtl ActiveX control in tgctlcm.dll in Consona Live Assistance, Dynamic Agent, and Subscriber Assistance allows remote attackers to discover the username of the client user, and consequently determine a pathname to a certain user directory, via a call to the GetUserName method.

CVSS 2.0
4.3 MEDIUMAV:N/AC:M/Au:N/C:P/I:N/A:N
EPSS
1.53% probability · 73th percentile
CISA KEV
Not listed
Weakness
CWE-200
Affected
consona/consona dynamic agent · consona/consona live assistance · consona/consona subscriber assistance
Source
cve@mitre.org

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.