PT-2002-2758 · Cisco+1 · Billing/Management Server+5
Published
2002-12-31
·
Updated
2008-09-05
·
CVE-2002-2037
CVSS v2.0
5.0
Medium
| Vector | AV:N/AC:L/Au:N/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
Cisco Media Gateway Controller (MGC) versions 7.4 and earlier
VSC3000 versions 9.1 and earlier
PGW 2200 versions 9.1 and earlier
Billing and Management Server (BAMS) (affected versions not specified)
Voice Services Provisioning Tool (VSPT) (affected versions not specified)
Description
The issue is related to the Cisco Media Gateway Controller (MGC) running on default installations of Solaris 2.6 with unnecessary services and without the latest security patches. This setup allows attackers to exploit known vulnerabilities.
Recommendations
For Cisco Media Gateway Controller (MGC) version 7.4 and earlier, update to a version with the latest security patches.
For VSC3000 version 9.1 and earlier, update to a version with the latest security patches.
For PGW 2200 version 9.1 and earlier, update to a version with the latest security patches.
For Billing and Management Server (BAMS), apply the latest security patches.
For Voice Services Provisioning Tool (VSPT), apply the latest security patches.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Billing/Management Server
Cisco Media Gateway Controller
Pgw 2200
Solaris
Vsc3000
Voice Services Provisioning Tool