CVE-2010-3040

UnknownEPSS 7.99%

Last modified

CVE-2010-3040 is a vulnerability of currently unknown severity. Multiple stack-based buffer overflows in agent.exe in Setup Manager in Cisco Intelligent Contact Manager (ICM) before 7.0 allow remote attackers to execute arbitrary code via a long parameter in a (1) HandleUpgradeAll, (2) AgentUpgrade, (3) HandleQueryNodeInfoReq, or (4) HandleUpgradeTrace TCP packet, aka Bug IDs CSCti45698, CSCti45715, CSCti45726, and CSCti46164.. EPSS estimates a 7.99% chance of exploitation in the next 30 days.

Description

Multiple stack-based buffer overflows in agent.exe in Setup Manager in Cisco Intelligent Contact Manager (ICM) before 7.0 allow remote attackers to execute arbitrary code via a long parameter in a (1) HandleUpgradeAll, (2) AgentUpgrade, (3) HandleQueryNodeInfoReq, or (4) HandleUpgradeTrace TCP packet, aka Bug IDs CSCti45698, CSCti45715, CSCti45726, and CSCti46164.

Metrics

EPSS Probability
7.99%

94.0th percentile

Probability of exploitation in the next 30 days. Learn more

Weakness Enumeration

Affected Software

VendorProductVersions
CiscoIntelligent Contact Manager<= 6.0\(0\)a\(1\)
CiscoIntelligent Contact Manager5.0
CiscoIntelligent Contact Manager5.0\(0\)
CiscoIntelligent Contact Manager5.0\(0\)_sr2
CiscoIntelligent Contact Manager5.0\(0\)_sr3
CiscoIntelligent Contact Manager5.0\(0\)_sr4
CiscoIntelligent Contact Manager5.0\(0\)_sr5
CiscoIntelligent Contact Manager5.0\(0\)_sr7
CiscoIntelligent Contact Manager5.0\(0\)_sr8
CiscoIntelligent Contact Manager5.0\(0\)_sr9
CiscoIntelligent Contact Manager5.0\(0\)_sr10
CiscoIntelligent Contact Manager5.0\(0\)_sr11
CiscoIntelligent Contact Manager5.0\(0\)_sr12
CiscoIntelligent Contact Manager5.0\(0\)_sr13
CiscoIntelligent Contact Manager5.0\(0\)a
CiscoIntelligent Contact Manager6.0\(0\)
CiscoIntelligent Contact Manager6.0\(0\)_sr1
CiscoIntelligent Contact Manager6.0\(0\)_sr2
CiscoIntelligent Contact Manager6.0\(0\)_sr3
CiscoIntelligent Contact Manager6.0\(0\)_sr4
CiscoIntelligent Contact Manager6.0\(0\)_sr5
CiscoIntelligent Contact Manager6.0\(0\)_sr6
CiscoIntelligent Contact Manager6.0\(0\)_sr7
CiscoIntelligent Contact Manager6.0\(0\)_sr8
CiscoIntelligent Contact Manager6.0\(0\)_sr9
CiscoIntelligent Contact Manager6.0\(0\)_sr10
CiscoIntelligent Contact Manager6.0\(0\)a

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2010-3040?
Multiple stack-based buffer overflows in agent.exe in Setup Manager in Cisco Intelligent Contact Manager (ICM) before 7.0 allow remote attackers to execute arbitrary code via a long parameter in a (1) HandleUpgradeAll, (2) AgentUpgrade, (3) HandleQueryNodeInfoReq, or (4) HandleUpgradeTrace TCP packet, aka Bug IDs CSCti45698, CSCti45715, CSCti45726, and CSCti46164.
How severe is CVE-2010-3040?
Severity scoring for CVE-2010-3040 is pending analysis. The EPSS model estimates a 7.99% probability of exploitation in the next 30 days.
How do I fix CVE-2010-3040?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2010-3040?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST