Cisco Personal Assistant 1.4(1) and 1.4(2) disables password authentication when "Allow Only Cisco CallManager Users" is enabled and the Corporate Directory settings refer to the directory service being used by Cisco CallManager, which allows remote attackers to gain access with a valid username.
References
Configurations
Configuration 1 (hide)
|
History
20 Nov 2024, 23:47
Type | Values Removed | Values Added |
---|---|---|
References | () http://www.cisco.com/warp/public/707/cisco-sa-20040108-pa.shtml - Patch, Vendor Advisory | |
References | () http://www.osvdb.org/3430 - | |
References | () http://www.securityfocus.com/bid/9384 - | |
References | () https://exchange.xforce.ibmcloud.com/vulnerabilities/14172 - |
Information
Published : 2004-02-03 05:00
Updated : 2024-11-20 23:47
NVD link : CVE-2004-0044
Mitre link : CVE-2004-0044
CVE.ORG link : CVE-2004-0044
JSON object : View
Products Affected
cisco
- personal_assistant
CWE