PT-2004-2664 · Ibm+1 · Ibm Director Agent+2
Published
2004-01-21
·
Updated
2017-07-11
·
CVE-2004-1760
CVSS v2.0
10
High
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Cisco voice products versions prior to OS 2000.2.6
Description
The issue concerns the default installation of Cisco voice products on IBM servers, where the IBM Director Agent does not require authentication. This allows remote attackers to gain administrator privileges by connecting to TCP port 14247.
Recommendations
For versions prior to OS 2000.2.6, update to OS 2000.2.6 or later to address the issue. As a temporary workaround, consider restricting access to TCP port 14247 to minimize the risk of exploitation.
Fix
Improper Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Cisco Voice Products
Ibm Director Agent
Ibm Servers