CVE-2010-3040

Multiple stack-based buffer overflows in agent.exe in Setup Manager in Cisco Intelligent Contact Manager (ICM) before 7.0 allow remote attackers to execute arbitrary code via a long parameter in a (1) HandleUpgradeAll, (2) AgentUpgrade, (3) HandleQueryNodeInfoReq, or (4) HandleUpgradeTrace TCP packet, aka Bug IDs CSCti45698, CSCti45715, CSCti45726, and CSCti46164.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
10 UNKNOWN
NETWORK
LOW
AV:N/AC:L/Au:N/C:C/I:C/A:C
ciscoCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 95%
VendorProductVersion
ciscointelligent_contact_manager
𝑥
≤ 6.0\(0\)a\(1\)
ciscointelligent_contact_manager
5.0
ciscointelligent_contact_manager
5.0\(0\)
ciscointelligent_contact_manager
5.0\(0\)_sr2
ciscointelligent_contact_manager
5.0\(0\)_sr3
ciscointelligent_contact_manager
5.0\(0\)_sr4
ciscointelligent_contact_manager
5.0\(0\)_sr5
ciscointelligent_contact_manager
5.0\(0\)_sr7
ciscointelligent_contact_manager
5.0\(0\)_sr8
ciscointelligent_contact_manager
5.0\(0\)_sr9
ciscointelligent_contact_manager
5.0\(0\)_sr10
ciscointelligent_contact_manager
5.0\(0\)_sr11
ciscointelligent_contact_manager
5.0\(0\)_sr12
ciscointelligent_contact_manager
5.0\(0\)_sr13
ciscointelligent_contact_manager
5.0\(0\)a
ciscointelligent_contact_manager
6.0\(0\)
ciscointelligent_contact_manager
6.0\(0\)_sr1
ciscointelligent_contact_manager
6.0\(0\)_sr2
ciscointelligent_contact_manager
6.0\(0\)_sr3
ciscointelligent_contact_manager
6.0\(0\)_sr4
ciscointelligent_contact_manager
6.0\(0\)_sr5
ciscointelligent_contact_manager
6.0\(0\)_sr6
ciscointelligent_contact_manager
6.0\(0\)_sr7
ciscointelligent_contact_manager
6.0\(0\)_sr8
ciscointelligent_contact_manager
6.0\(0\)_sr9
ciscointelligent_contact_manager
6.0\(0\)_sr10
ciscointelligent_contact_manager
6.0\(0\)a
𝑥
= Vulnerable software versions