PT-2004-1259 · Cisco · Cisco Personal Assistant+1

Published

2004-02-03

·

Updated

2017-10-10

·

CVE-2004-0044

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Cisco Personal Assistant versions 1.4(1) through 1.4(2)
Description The issue allows remote attackers to gain access with a valid username when password authentication is disabled due to specific configuration settings. This occurs when "Allow Only Cisco CallManager Users" is enabled and the Corporate Directory settings refer to the directory service being used by Cisco CallManager.
Recommendations For Cisco Personal Assistant versions 1.4(1) and 1.4(2), consider disabling the "Allow Only Cisco CallManager Users" feature until a patch is available, or ensure that an alternative authentication method is enforced to prevent unauthorized access.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2004-0044

Affected Products

Cisco Callmanager
Cisco Personal Assistant