SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2010-1910

The Forgot Password implementation in Consona Live Assistance, Dynamic Agent, and Subscriber Assistance allows remote attackers to reset passwords of accounts with blank Hint questions and Hint answers by sending an empty value for each of these two…

MEDIUM 5.1EPSS 2.46%

Does this matter?

Lower severity and a low EPSS score (2.46%). Track it; it rarely justifies an emergency change on its own.

Description

The Forgot Password implementation in Consona Live Assistance, Dynamic Agent, and Subscriber Assistance allows remote attackers to reset passwords of accounts with blank Hint questions and Hint answers by sending an empty value for each of these two Hint fields.

CVSS 2.0
5.1 MEDIUMAV:N/AC:H/Au:N/C:P/I:P/A:P
EPSS
2.46% probability · 84th percentile
CISA KEV
Not listed
Weakness
CWE-287
Affected
consona/consona dynamic agent · consona/consona live assistance · consona/consona subscriber assistance
Source
cve@mitre.org

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.