PT-2004-1259 · Cisco · Cisco Personal Assistant+1
Publicado
2004-02-03
·
Atualizado
2017-10-10
·
CVE-2004-0044
CVSS v2.0
7.5
Alta
| Vetor | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Cisco Personal Assistant versions 1.4(1) through 1.4(2)
Description
The issue allows remote attackers to gain access with a valid username when password authentication is disabled due to specific configuration settings. This occurs when "Allow Only Cisco CallManager Users" is enabled and the Corporate Directory settings refer to the directory service being used by Cisco CallManager.
Recommendations
For Cisco Personal Assistant versions 1.4(1) and 1.4(2), consider disabling the "Allow Only Cisco CallManager Users" feature until a patch is available, or ensure that an alternative authentication method is enforced to prevent unauthorized access.
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Cisco Callmanager
Cisco Personal Assistant