CVE-2010-3040 - CVE House
Back to Database
Status published Critical CVE-2010-3040

Multiple stack-based buffer overflows in agent.exe in Setup Manager in...

Vulnerability Description

Multiple stack-based buffer overflows in agent.exe in Setup Manager in Cisco Intelligent Contact Manager (ICM) before 7.0 allow remote attackers to execute arbitrary code via a long parameter in a (1) HandleUpgradeAll, (2) AgentUpgrade, (3) HandleQueryNodeInfoReq, or (4) HandleUpgradeTrace TCP packet, aka Bug IDs CSCti45698, CSCti45715, CSCti45726, and CSCti46164.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2010-3040

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Affected Software

intelligent contact manager
Vulnerable Versions:
0, 5.0, 5.0\(0\), 5.0\(0\)_sr2, 5.0\(0\)_sr3, 5.0\(0\)_sr4, 5.0\(0\)_sr5, 5.0\(0\)_sr7, 5.0\(0\)_sr8, 5.0\(0\)_sr9, 5.0\(0\)_sr10, 5.0\(0\)_sr11, 5.0\(0\)_sr12, 5.0\(0\)_sr13, 5.0\(0\)a, 6.0\(0\), 6.0\(0\)_sr1, 6.0\(0\)_sr2, 6.0\(0\)_sr3, 6.0\(0\)_sr4, 6.0\(0\)_sr5, 6.0\(0\)_sr6, 6.0\(0\)_sr7, 6.0\(0\)_sr8, 6.0\(0\)_sr9, 6.0\(0\)_sr10, 6.0\(0\)a

Timeline

Official Publish: November 9th, 2010
Last Modified: September 16th, 2024
Added to House: July 19th, 2026

CVSS Vectors

Weaknesses (CWE)

No CWE data available

MITRE ATT&CK TTPs

No associated TTPs found for this vulnerability.