PT-2004-2664 · Ibm+1 · Ibm Director Agent+2
Publicado
2004-01-21
·
Atualizado
2017-07-11
·
CVE-2004-1760
CVSS v2.0
10
Alta
| Vetor | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Cisco voice products versions prior to OS 2000.2.6
Description
The issue concerns the default installation of Cisco voice products on IBM servers, where the IBM Director Agent does not require authentication. This allows remote attackers to gain administrator privileges by connecting to TCP port 14247.
Recommendations
For versions prior to OS 2000.2.6, update to OS 2000.2.6 or later to address the issue. As a temporary workaround, consider restricting access to TCP port 14247 to minimize the risk of exploitation.
Correção
Improper Authentication
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Cisco Voice Products
Ibm Director Agent
Ibm Servers