HIGH · 7.5

CVE-2003-0983

Cisco Unity on IBM servers is shipped with default settings that should have been disabled by the manufacturer, which allows local or remote attackers to conduct unauthorized activities via (1) a "bub...

Vulnerability Description

Cisco Unity on IBM servers is shipped with default settings that should have been disabled by the manufacturer, which allows local or remote attackers to conduct unauthorized activities via (1) a "bubba" local user account, (2) an open TCP port 34571, or (3) when a local DHCP server is unavailable, a DHCP server on the manufacturer's test network.

CVSS Score

7.5

HIGH

AV:N/AC:L/Au:N/C:P/I:P/A:P
Confidentiality
PARTIAL
Integrity
PARTIAL
Availability
PARTIAL

Affected Products

VendorProductVersions
Cisco80-7111-01 For The Unity-Svrx255-1AAll versions
Cisco80-7112-01 For The Unity-Svrx255-2AAll versions

References

FAQ

What is CVE-2003-0983?

CVE-2003-0983 is a vulnerability with a CVSS score of 7.5 (HIGH). Cisco Unity on IBM servers is shipped with default settings that should have been disabled by the manufacturer, which allows local or remote attackers to conduct unauthorized activities via (1) a "bub...

How severe is CVE-2003-0983?

CVE-2003-0983 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2003-0983?

Check the references section above for vendor advisories and patch information. Affected products include: Cisco 80-7111-01 For The Unity-Svrx255-1A, Cisco 80-7112-01 For The Unity-Svrx255-2A.