PT-2005-1658 · Cisco · Cisco Ip/Vc Videoconferencing System
Published
2005-03-02
·
Updated
2008-09-05
·
CVE-2005-0612
CVSS v2.0
7.5
High
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Cisco IP/VC Videoconferencing System versions 3510, 3520, 3525, and 3530
Description
The issue allows remote attackers to gain access, cause a denial of service, and modify configuration due to hard-coded default SNMP community strings.
Recommendations
For versions 3510, 3520, 3525, and 3530, consider changing the default SNMP community strings to custom, secure values to prevent unauthorized access.
As a temporary workaround, restrict access to the SNMP service until a patch is available.
Avoid using default configuration settings for SNMP community strings in the affected systems to minimize the risk of exploitation.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Cisco Ip/Vc Videoconferencing System