PT-2004-1259 · Cisco · Cisco Personal Assistant+1
Published
2004-02-03
·
Updated
2017-10-10
·
CVE-2004-0044
CVSS v2.0
7.5
High
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Cisco Personal Assistant versions 1.4(1) through 1.4(2)
Description
The issue allows remote attackers to gain access with a valid username when password authentication is disabled due to specific configuration settings. This occurs when "Allow Only Cisco CallManager Users" is enabled and the Corporate Directory settings refer to the directory service being used by Cisco CallManager.
Recommendations
For Cisco Personal Assistant versions 1.4(1) and 1.4(2), consider disabling the "Allow Only Cisco CallManager Users" feature until a patch is available, or ensure that an alternative authentication method is enforced to prevent unauthorized access.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Cisco Callmanager
Cisco Personal Assistant