HIGH · 10.0

CVE-2004-1760

The default installation of Cisco voice products, when running the IBM Director Agent on IBM servers before OS 2000.2.6, does not require authentication, which allows remote attackers to gain administ...

Vulnerability Description

The default installation of Cisco voice products, when running the IBM Director Agent on IBM servers before OS 2000.2.6, does not require authentication, which allows remote attackers to gain administrator privileges by connecting to TCP port 14247.

CVSS Score

10.0

HIGH

AV:N/AC:L/Au:N/C:C/I:C/A:C
Confidentiality
COMPLETE
Integrity
COMPLETE
Availability
COMPLETE

Affected Products

VendorProductVersions
CiscoEmergency Responder1.1
CiscoIp Call Center Express Enhanced3.0
CiscoIp Call Center Express Standard3.0
CiscoIp Interactive Voice Response3.0
CiscoPersonal Assistant1.3\(1\)
IbmDirector Agent2.2
CiscoCall Manager1.0
CiscoInternet Service NodeAll versions
CiscoConference Connection1.1\(1\)
IbmMcs-7815-1000All versions
IbmMcs-7815I-2.0All versions
IbmMcs-7835I-2.4All versions
IbmMcs-7835I-3.0All versions
IbmX3308654
IbmX340All versions
IbmX342All versions
IbmX345All versions

Related Weaknesses (CWE)

References

FAQ

What is CVE-2004-1760?

CVE-2004-1760 is a vulnerability with a CVSS score of 10.0 (HIGH). The default installation of Cisco voice products, when running the IBM Director Agent on IBM servers before OS 2000.2.6, does not require authentication, which allows remote attackers to gain administ...

How severe is CVE-2004-1760?

CVE-2004-1760 has been rated HIGH with a CVSS base score of 10.0/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2004-1760?

Check the references section above for vendor advisories and patch information. Affected products include: Cisco Emergency Responder, Cisco Ip Call Center Express Enhanced, Cisco Ip Call Center Express Standard, Cisco Ip Interactive Voice Response, Cisco Personal Assistant.