CVE-2004-1760
Summary
| CVE | CVE-2004-1760 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2004-01-21 05:00:00 UTC |
| Updated | 2017-07-11 01:31:00 UTC |
| Description | The default installation of Cisco voice products, when running the IBM Director Agent on IBM servers before OS 2000.2.6, does not require authentication, which allows remote attackers to gain administrator privileges by connecting to TCP port 14247. |
Risk And Classification
Problem Types: CWE-287
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Hardware | Cisco | Call Manager | 1.0 | All | All | All |
| Hardware | Cisco | Call Manager | 2.0 | All | All | All |
| Hardware | Cisco | Call Manager | 3.0 | All | All | All |
| Hardware | Cisco | Call Manager | 3.1 | All | All | All |
| Hardware | Cisco | Call Manager | 3.1(2) | All | All | All |
| Hardware | Cisco | Call Manager | 3.1(3a) | All | All | All |
| Hardware | Cisco | Call Manager | 3.1\(2\) | All | All | All |
| Hardware | Cisco | Call Manager | 3.1\(3a\) | All | All | All |
| Hardware | Cisco | Call Manager | 3.2 | All | All | All |
| Hardware | Cisco | Call Manager | 3.3 | All | All | All |
| Hardware | Cisco | Call Manager | 3.3(3) | All | All | All |
| Hardware | Cisco | Call Manager | 3.3\(3\) | All | All | All |
| Hardware | Cisco | Call Manager | 4.0 | All | All | All |
| Hardware | Cisco | Call Manager | 1.0 | All | All | All |
| Hardware | Cisco | Call Manager | 2.0 | All | All | All |
| Hardware | Cisco | Call Manager | 3.0 | All | All | All |
| Hardware | Cisco | Call Manager | 3.1 | All | All | All |
| Hardware | Cisco | Call Manager | 3.1\(2\) | All | All | All |
| Hardware | Cisco | Call Manager | 3.1\(3a\) | All | All | All |
| Hardware | Cisco | Call Manager | 3.2 | All | All | All |
| Hardware | Cisco | Call Manager | 3.3 | All | All | All |
| Hardware | Cisco | Call Manager | 3.3\(3\) | All | All | All |
| Hardware | Cisco | Call Manager | 4.0 | All | All | All |
| Operating System | Cisco | Conference Connection | 1.1(1) | All | All | All |
| Operating System | Cisco | Conference Connection | 1.1\(1\) | All | All | All |
| Operating System | Cisco | Conference Connection | 1.2 | All | All | All |
| Operating System | Cisco | Conference Connection | 1.1\(1\) | All | All | All |
| Operating System | Cisco | Conference Connection | 1.2 | All | All | All |
| Application | Cisco | Emergency Responder | 1.1 | All | All | All |
| Application | Cisco | Emergency Responder | 1.1 | All | All | All |
| Hardware | Cisco | Internet Service Node | All | All | All | All |
| Hardware | Cisco | Internet Service Node | All | All | All | All |
| Application | Cisco | Ip Call Center Express Enhanced | 3.0 | All | All | All |
| Application | Cisco | Ip Call Center Express Enhanced | 3.0 | All | All | All |
| Application | Cisco | Ip Call Center Express Standard | 3.0 | All | All | All |
| Application | Cisco | Ip Call Center Express Standard | 3.0 | All | All | All |
| Application | Cisco | Ip Interactive Voice Response | 3.0 | All | All | All |
| Application | Cisco | Ip Interactive Voice Response | 3.0 | All | All | All |
| Application | Cisco | Personal Assistant | 1.3(1) | All | All | All |
| Application | Cisco | Personal Assistant | 1.3(2) | All | All | All |
| Application | Cisco | Personal Assistant | 1.3(3) | All | All | All |
| Application | Cisco | Personal Assistant | 1.3(4) | All | All | All |
| Application | Cisco | Personal Assistant | 1.3\(1\) | All | All | All |
| Application | Cisco | Personal Assistant | 1.3\(2\) | All | All | All |
| Application | Cisco | Personal Assistant | 1.3\(3\) | All | All | All |
| Application | Cisco | Personal Assistant | 1.3\(4\) | All | All | All |
| Application | Cisco | Personal Assistant | 1.4(1) | All | All | All |
| Application | Cisco | Personal Assistant | 1.4(2) | All | All | All |
| Application | Cisco | Personal Assistant | 1.4\(1\) | All | All | All |
| Application | Cisco | Personal Assistant | 1.4\(2\) | All | All | All |
| Application | Cisco | Personal Assistant | 1.3\(1\) | All | All | All |
| Application | Cisco | Personal Assistant | 1.3\(2\) | All | All | All |
| Application | Cisco | Personal Assistant | 1.3\(3\) | All | All | All |
| Application | Cisco | Personal Assistant | 1.3\(4\) | All | All | All |
| Application | Cisco | Personal Assistant | 1.4\(1\) | All | All | All |
| Application | Cisco | Personal Assistant | 1.4\(2\) | All | All | All |
| Application | Ibm | Director Agent | 2.2 | All | All | All |
| Application | Ibm | Director Agent | 3.11 | All | All | All |
| Application | Ibm | Director Agent | 2.2 | All | All | All |
| Application | Ibm | Director Agent | 3.11 | All | All | All |
| Hardware | Ibm | Mcs-7815-1000 | All | All | All | All |
| Hardware | Ibm | Mcs-7815-1000 | All | All | All | All |
| Hardware | Ibm | Mcs-7815i-2.0 | All | All | All | All |
| Hardware | Ibm | Mcs-7815i-2.0 | All | All | All | All |
| Hardware | Ibm | Mcs-7835i-2.4 | All | All | All | All |
| Hardware | Ibm | Mcs-7835i-2.4 | All | All | All | All |
| Hardware | Ibm | Mcs-7835i-3.0 | All | All | All | All |
| Hardware | Ibm | Mcs-7835i-3.0 | All | All | All | All |
| Hardware | Ibm | X330 | 8654 | All | All | All |
| Hardware | Ibm | X330 | 8674 | All | All | All |
| Hardware | Ibm | X330 | 8654 | All | All | All |
| Hardware | Ibm | X330 | 8674 | All | All | All |
| Hardware | Ibm | X340 | All | All | All | All |
| Hardware | Ibm | X340 | All | All | All | All |
| Hardware | Ibm | X342 | All | All | All | All |
| Hardware | Ibm | X342 | All | All | All | All |
| Hardware | Ibm | X345 | All | All | All | All |
| Hardware | Ibm | X345 | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| 3692 | OSVDB | www.osvdb.org | |
| Cisco Personal Assistant Default Configuration on IBM Servers Grants Administrative Access to Remote Users - SecurityTracker | SECTRACK | www.securitytracker.com | |
| Secunia - Advisories - Cisco Voice Products Director Agent Insecure Default Installation | SECUNIA | secunia.com | Patch, Vendor Advisory |
| Cisco Voice Product IBM Director Agent Unauthorized Remote Administrative Access Vulnerability | BID | www.securityfocus.com | Patch, Vendor Advisory |
| O-066 | CIAC | www.ciac.org | |
| IBM X-Force Exchange | XF | exchange.xforce.ibmcloud.com | |
| US-CERT Vulnerability Note VU#602734 | CERT-VN | www.kb.cert.org | Patch, Third Party Advisory, US Government Resource |
| Cisco - Networking, Cloud, and Cybersecurity Solutions | CISCO | www.cisco.com | Patch, Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.