PT-2004-2245 · Microsoft+1 · Exchange Server+1

Published

2004-12-15

·

Updated

2017-07-11

·

CVE-2004-1322

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions: Cisco Unity versions 2.x through 4.x
Description: The issue allows remote attackers to gain unauthorized access and change configuration settings or read outgoing or incoming e-mail messages due to several hard-coded usernames and passwords when Cisco Unity is integrated with Microsoft Exchange.
Recommendations: For versions 2.x through 4.x, consider changing the hard-coded usernames and passwords to unique and secure credentials as a temporary workaround, and restrict access to configuration settings and e-mail messages until a more permanent solution is available.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2004-1322

Affected Products

Cisco Unity
Exchange Server