HIGH · 7.5

CVE-2002-0628

The Telnet service for Polycom ViewStation before 7.2.4 does not restrict the number of failed login attempts, which makes it easier for remote attackers to guess usernames and passwords via a brute f...

Vulnerability Description

The Telnet service for Polycom ViewStation before 7.2.4 does not restrict the number of failed login attempts, which makes it easier for remote attackers to guess usernames and passwords via a brute force attack.

CVSS Score

7.5

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
HIGH
Integrity
NONE
Availability
NONE

Affected Products

VendorProductVersions
PolycomViewstation 1286.5.1
PolycomViewstation 5126.5.1
PolycomViewstation Dcp6.5.1
PolycomViewstation Fx Vs40004.1.5
PolycomViewstation H.3236.5.1
PolycomViewstation Mp6.5.1
PolycomViewstation Sp 3846.5.1
PolycomViewstation V.356.5.1

Related Weaknesses (CWE)

References

FAQ

What is CVE-2002-0628?

CVE-2002-0628 is a vulnerability with a CVSS score of 7.5 (HIGH). The Telnet service for Polycom ViewStation before 7.2.4 does not restrict the number of failed login attempts, which makes it easier for remote attackers to guess usernames and passwords via a brute f...

How severe is CVE-2002-0628?

CVE-2002-0628 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2002-0628?

Check the references section above for vendor advisories and patch information. Affected products include: Polycom Viewstation 128, Polycom Viewstation 512, Polycom Viewstation Dcp, Polycom Viewstation Fx Vs4000, Polycom Viewstation H.323.