Vulnerability Description
The default configuration of the HTTP server in Hitachi IP5000 VOIP WIFI Phone 1.5.6 does not require authentication for sensitive configuration pages, which allows remote attackers to modify configuration.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Hitachi | Ip5000 Voip Wifi Phone | 1.5.0 |
References
- http://marc.info/?l=full-disclosure&m=113217425618951&w=2
- http://secunia.com/advisories/17628PatchVendor Advisory
- http://www.hitachi-cable.co.jp/ICSFiles/infosystem/security/76659792_e.pdf
- http://marc.info/?l=full-disclosure&m=113217425618951&w=2
- http://secunia.com/advisories/17628PatchVendor Advisory
- http://www.hitachi-cable.co.jp/ICSFiles/infosystem/security/76659792_e.pdf
FAQ
What is CVE-2005-3721?
CVE-2005-3721 is a vulnerability with a CVSS score of 5.0 (MEDIUM). The default configuration of the HTTP server in Hitachi IP5000 VOIP WIFI Phone 1.5.6 does not require authentication for sensitive configuration pages, which allows remote attackers to modify configur...
How severe is CVE-2005-3721?
CVE-2005-3721 has been rated MEDIUM with a CVSS base score of 5.0/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2005-3721?
Check the references section above for vendor advisories and patch information. Affected products include: Hitachi Ip5000 Voip Wifi Phone.