CVE-2002-0628

The Telnet service for Polycom ViewStation before 7.2.4 does not restrict the number of failed login attempts, which makes it easier for remote attackers to guess usernames and passwords via a brute force attack.
Configurations

Configuration 1 (hide)

OR cpe:2.3:h:polycom:viewstation_128:6.5.1:*:*:*:*:*:*:*
cpe:2.3:h:polycom:viewstation_128:7.2:*:*:*:*:*:*:*
cpe:2.3:h:polycom:viewstation_512:6.5.1:*:*:*:*:*:*:*
cpe:2.3:h:polycom:viewstation_512:7.2:*:*:*:*:*:*:*
cpe:2.3:h:polycom:viewstation_dcp:6.5.1:*:*:*:*:*:*:*
cpe:2.3:h:polycom:viewstation_dcp:7.2:*:*:*:*:*:*:*
cpe:2.3:h:polycom:viewstation_fx_vs4000:4.1.5:*:*:*:*:*:*:*
cpe:2.3:h:polycom:viewstation_h.323:6.5.1:*:*:*:*:*:*:*
cpe:2.3:h:polycom:viewstation_h.323:7.2:*:*:*:*:*:*:*
cpe:2.3:h:polycom:viewstation_mp:6.5.1:*:*:*:*:*:*:*
cpe:2.3:h:polycom:viewstation_mp:7.2:*:*:*:*:*:*:*
cpe:2.3:h:polycom:viewstation_sp_384:6.5.1:*:*:*:*:*:*:*
cpe:2.3:h:polycom:viewstation_sp_384:7.2:*:*:*:*:*:*:*
cpe:2.3:h:polycom:viewstation_v.35:6.5.1:*:*:*:*:*:*:*
cpe:2.3:h:polycom:viewstation_v.35:7.2:*:*:*:*:*:*:*

History

20 Nov 2024, 23:39

Type Values Removed Values Added
References () http://bvlive01.iss.net/issEn/delivery/xforce/alertdetail.jsp?oid=21089 - Broken Link () http://bvlive01.iss.net/issEn/delivery/xforce/alertdetail.jsp?oid=21089 - Broken Link
References () http://www.ciac.org/ciac/bulletins/m-123.shtml - Broken Link, Patch, Vendor Advisory () http://www.ciac.org/ciac/bulletins/m-123.shtml - Broken Link, Patch, Vendor Advisory
References () http://www.iss.net/security_center/static/9349.php - Broken Link, Vendor Advisory () http://www.iss.net/security_center/static/9349.php - Broken Link, Vendor Advisory
References () http://www.polycom.com/common/pw_item_show_doc/0%2C%2C1444%2C00.pdf - Product () http://www.polycom.com/common/pw_item_show_doc/0%2C%2C1444%2C00.pdf - Product
References () http://www.securityfocus.com/bid/5635 - Broken Link, Third Party Advisory, VDB Entry, Vendor Advisory () http://www.securityfocus.com/bid/5635 - Broken Link, Third Party Advisory, VDB Entry, Vendor Advisory
References () https://exchange.xforce.ibmcloud.com/vulnerabilities/44241 - Third Party Advisory, VDB Entry () https://exchange.xforce.ibmcloud.com/vulnerabilities/44241 - Third Party Advisory, VDB Entry

09 Feb 2024, 03:14

Type Values Removed Values Added
CWE NVD-CWE-Other CWE-307
References (BID) http://www.securityfocus.com/bid/5635 - Vendor Advisory (BID) http://www.securityfocus.com/bid/5635 - Broken Link, Third Party Advisory, VDB Entry, Vendor Advisory
References (CIAC) http://www.ciac.org/ciac/bulletins/m-123.shtml - Patch, Vendor Advisory (CIAC) http://www.ciac.org/ciac/bulletins/m-123.shtml - Broken Link, Patch, Vendor Advisory
References (XF) http://www.iss.net/security_center/static/9349.php - Vendor Advisory (XF) http://www.iss.net/security_center/static/9349.php - Broken Link, Vendor Advisory
References (XF) https://exchange.xforce.ibmcloud.com/vulnerabilities/44241 - (XF) https://exchange.xforce.ibmcloud.com/vulnerabilities/44241 - Third Party Advisory, VDB Entry
References (ISS) http://bvlive01.iss.net/issEn/delivery/xforce/alertdetail.jsp?oid=21089 - (ISS) http://bvlive01.iss.net/issEn/delivery/xforce/alertdetail.jsp?oid=21089 - Broken Link
References () http://www.polycom.com/common/pw_item_show_doc/0%2C%2C1444%2C00.pdf - () http://www.polycom.com/common/pw_item_show_doc/0%2C%2C1444%2C00.pdf - Product
CVSS v2 : 5.0
v3 : unknown
v2 : 5.0
v3 : 7.5

07 Nov 2023, 01:55

Type Values Removed Values Added
References
  • {'url': 'http://www.polycom.com/common/pw_item_show_doc/0,,1444,00.pdf', 'name': 'http://www.polycom.com/common/pw_item_show_doc/0,,1444,00.pdf', 'tags': [], 'refsource': 'CONFIRM'}
  • () http://www.polycom.com/common/pw_item_show_doc/0%2C%2C1444%2C00.pdf -

Information

Published : 2003-01-07 05:00

Updated : 2024-11-20 23:39


NVD link : CVE-2002-0628

Mitre link : CVE-2002-0628

CVE.ORG link : CVE-2002-0628


JSON object : View

Products Affected

polycom

  • viewstation_v.35
  • viewstation_mp
  • viewstation_128
  • viewstation_h.323
  • viewstation_sp_384
  • viewstation_dcp
  • viewstation_fx_vs4000
  • viewstation_512
CWE
CWE-307

Improper Restriction of Excessive Authentication Attempts