copyright
|
disclaimer
|
privacy
|
contact
HOME
About
AusCERT
Membership
Contact Us
PKI Services
Training
Publications
Sec. Bulletins
Conferences
News & Media
Services
Web Log
Site Map
Site Help
Member login
Login »
Become a member »
Home
»
Security Bul...
»
Security Bul...
»
AusCERT Secu...
» ASB-2010.0215 - [Win] Alcatel-Lucent OmniTouch CCAge...
ASB-2010.0215 - [Win] Alcatel-Lucent OmniTouch CCAgent: Denial of service - Remote/unauthenticated
Date:
22 September 2010
Click here for printable version
-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 =========================================================================== AUSCERT Security Bulletin ASB-2010.0215 Alcatel-Lucent: CCAgent vulnerability permits unauthorised access to TSA server 22 September 2010 =========================================================================== AusCERT Security Bulletin Summary --------------------------------- Product: Alcatel-Lucent OmniTouch CCAgent Operating System: Windows Impact/Access: Denial of Service -- Remote/Unauthenticated Resolution: Mitigation CVE Names: CVE-2010-3279 CVE-2010-3280 Member content until: Friday, October 22 2010 OVERVIEW Alcatel-Lucent has reported two vulnerabilities in the OmniTouch Contact Center Standard Edition product. An attacker can leverage this vulnerability to gain access to the OmniTouch TSA server and alter the system configuration, leading to a potential complete denial of service (DoS). IMPACT The CCAgent option of the OmniTouch Contact Center Standard Edition is the vector for these vulnerabilities, which impact the management server (TSA). Exploiting the CCAgent permits access to the configuration of the OmniTouch TSA server and can result in complete denial of service (DoS) of the service. MITIGATION Alcatel-Lucent has released security bulletin 2010001 to address this issue [1] n.runs AG has published an advisory on this issue; it is available from http://www.nruns.com/_downloads/nruns-SA-2010-001.pdf Alcatel-Lucent maintains a list of Security Advisories for its products at http://www.alcatel-lucent.com/security/psirt REFERENCES [1] Alcatel-Lucent security bulletin 2010001 http://www.alcatel-lucent.com/security/psirt AusCERT has made every effort to ensure that the information contained in this document is accurate. However, the decision to use the information described is the responsibility of each user or organisation. The decision to follow or act on information or advice contained in this security bulletin is the responsibility of each user or organisation, and should be considered in accordance with your organisation's site policies and procedures. AusCERT takes no responsibility for consequences which may arise from following or acting on information or advice contained in this security bulletin. =========================================================================== Australian Computer Emergency Response Team The University of Queensland Brisbane Qld 4072 Internet Email: auscert@auscert.org.au Facsimile: (07) 3365 7031 Telephone: (07) 3365 4417 (International: +61 7 3365 4417) AusCERT personnel answer during Queensland business hours which are GMT+10:00 (AEST). On call after hours for member emergencies only. =========================================================================== -----BEGIN PGP SIGNATURE----- Comment: http://www.auscert.org.au/render.html?it=1967 iD8DBQFMmV/q/iFOrG6YcBERAmdfAKC1pOIB0NH6lqm6e8KHVjB04mYpxwCgnzgA WHYEH7mj783AFP4WBPmgWOg= =Z1g3 -----END PGP SIGNATURE-----
Comments? Click here
http://www.auscert.org.au/render.html?cid=10415&it=13384