Consona maintains a narrowly focused portfolio of customer-service and enterprise-support software, including dynamic agent, live assistance, and subscriber-management products that handle sensitive customer data and authentication workflows. The vendor's vulnerability surface recurs through information-disclosure, authentication, cross-site scripting, and memory-safety weakness classes that reflect the web-application and data-handling nature of its platform. Public exploit code has been available for this vendor's disclosed flaws; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Consona over time
Signals from CVEs in this vendor scope (9 CVEs).
9 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2010-1913HIGH The default configuration of pluginlicense.ini for the SdcWebSecureBase interface in tgctlcm.dll in Consona Live Assistance, Dynamic Agent, and Subscriber Assistance, when download | May 12, 2010 | 9.3 | 26 | NO | NO |
CVE-2010-1912HIGH The SdcWebSecureBase interface in tgctlcm.dll in Consona Live Assistance, Dynamic Agent, and Subscriber Assistance allows remote attackers to bypass intended restrictions on Active | May 12, 2010 | 9.3 | 26 | NO | NO |
CVE-2010-1911HIGH The site-locking implementation in the SdcWebSecureBase interface in tgctlcm.dll in Consona Live Assistance, Dynamic Agent, and Subscriber Assistance relies on a list of server dom | May 12, 2010 | 9.3 | 25 | NO | NO |
CVE-2010-1908HIGH The SdcUser.TgConCtl ActiveX control in tgctlcm.dll in Consona Live Assistance, Dynamic Agent, and Subscriber Assistance does not properly restrict access to the HTTPDownloadFile, | May 12, 2010 | 9.3 | 25 | NO | NO |
CVE-2010-1909HIGH Buffer overflow in the RunCmd method in the SdcUser.TgConCtl ActiveX control in tgctlcm.dll in Consona Live Assistance, Dynamic Agent, and Subscriber Assistance allows remote attac | May 12, 2010 | 7.6 | 23 | NO | NO |
CVE-2010-1905MEDIUM Multiple cross-site scripting (XSS) vulnerabilities in Consona Live Assistance, Dynamic Agent, and Subscriber Assistance allow remote attackers to inject arbitrary web script or HT | May 12, 2010 | 4.3 | 23 | NO | YES |
CVE-2010-1906HIGH tgsrv.exe in the Repair Service in Consona Dynamic Agent, Repair Manager, Subscriber Activation, and Subscriber Agent relies on a predictable timestamp field to validate input to t | May 12, 2010 | 7.2 | 22 | NO | NO |
CVE-2010-1910MEDIUM The Forgot Password implementation in Consona Live Assistance, Dynamic Agent, and Subscriber Assistance allows remote attackers to reset passwords of accounts with blank Hint quest | May 12, 2010 | 5.1 | 19 | NO | NO |
CVE-2010-1907MEDIUM The SdcUser.TgConCtl ActiveX control in tgctlcm.dll in Consona Live Assistance, Dynamic Agent, and Subscriber Assistance allows remote attackers to discover the username of the cli | May 12, 2010 | 4.3 | 16 | NO | NO |
Signals from CVEs in this vendor scope (9 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Consona.
Media articles that mention a CVE ID that affects a product developed by Consona — matched by CVE ID, not by vendor name.