Executive Summary



This Alert is flagged as TOP 25 Common Weakness Enumeration from CWE/SANS. For more information, you can read this.
Summary
Title Cisco Unified IP Conference Station and IP Phone Vulnerabilities
Informations
Name cisco-sa-20070221-phone First vendor Publication 2007-01-25
Vendor Cisco Last vendor Modification 2007-02-21
Severity (Vendor) N/A Revision N/A

Security-Database Scoring CVSS v3

Cvss vector : N/A
Overall CVSS Score NA
Base Score NA Environmental Score NA
impact SubScore NA Temporal Score NA
Exploitabality Sub Score NA
 
Calculate full CVSS 3.0 Vectors scores

Security-Database Scoring CVSS v2

Cvss vector : (AV:N/AC:L/Au:N/C:C/I:C/A:C)
Cvss Base Score 10 Attack Range Network
Cvss Impact Score 10 Attack Complexity Low
Cvss Expoit Score 10 Authentication None Required
Calculate full CVSS 2.0 Vectors scores

Detail

Certain Cisco Unified IP Conference Station and IP Phone devices contain vulnerabilities which may allow unauthorized users to gain administrative access to vulnerable devices.

Original Source

Url : http://www.cisco.com/warp/public/707/cisco-sa-20070221-phone.shtml

CAPEC : Common Attack Pattern Enumeration & Classification

Id Name
CAPEC-87 Forceful Browsing

CWE : Common Weakness Enumeration

% Id Name
33 % CWE-798 Use of Hard-coded Credentials (CWE/SANS Top 25)
33 % CWE-287 Improper Authentication
33 % CWE-264 Permissions, Privileges, and Access Controls

CPE : Common Platform Enumeration

TypeDescriptionCount
Os 1
Os 1
Os 1
Os 1
Os 1
Os 1

Open Source Vulnerability Database (OSVDB)

Id Description
45246 Cisco Unified IP Phone SSH Server Hard-coded Default Account

45245 Cisco Unified IP Phone Administrator HTTP Session Direct Request Authenticati...

33064 Cisco Unified IP Phone CLI Unspecified Local Privilege Escalation