{"api_version":"1","generated_at":"2026-04-23T09:52:21+00:00","cve":"CVE-2004-1322","urls":{"html":"https://cve.report/CVE-2004-1322","api":"https://cve.report/api/cve/CVE-2004-1322.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2004-1322","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2004-1322"},"summary":{"title":"CVE-2004-1322","description":"Cisco Unity 2.x, 3.x, and 4.x, when integrated with Microsoft Exchange, has several hard coded usernames and passwords, which allows remote attackers to gain unauthorized access and change configuration settings or read outgoing or incoming e-mail messages.","state":"PUBLISHED","assigner":"mitre","published_at":"2004-12-15 05:00:00","updated_at":"2025-04-03 01:03:51"},"problem_types":["NVD-CWE-Other","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"7.5","severity":"","vector":"AV:N/AC:L/Au:N/C:P/I:P/A:P","data":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:P/A:P","baseScore":7.5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"}}],"references":[{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/18489","name":"https://exchange.xforce.ibmcloud.com/vulnerabilities/18489","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"IBM X-Force Exchange","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.ciac.org/ciac/bulletins/p-060.shtml","name":"http://www.ciac.org/ciac/bulletins/p-060.shtml","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch","Vendor Advisory"],"title":"P-060: Cisco Unity with Exchange Default Passwords Vulnerability","mime":"text/html","httpstatus":"-1","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/11954","name":"http://www.securityfocus.com/bid/11954","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch","Vendor Advisory"],"title":"Cisco Unity With Exchange Default User Accounts and Passwords Vulnerability","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"http://www.cisco.com/warp/public/707/cisco-sa-20041215-unity.shtml","name":"http://www.cisco.com/warp/public/707/cisco-sa-20041215-unity.shtml","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch","Vendor Advisory"],"title":"Cisco - Networking, Cloud, and Cybersecurity Solutions","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2004-1322","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2004-1322","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2004","cve_id":"1322","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"h","cpe4":"cisco","cpe5":"unity_server","cpe6":"2.0","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2004","cve_id":"1322","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"h","cpe4":"cisco","cpe5":"unity_server","cpe6":"2.1","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2004","cve_id":"1322","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"h","cpe4":"cisco","cpe5":"unity_server","cpe6":"2.2","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2004","cve_id":"1322","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"h","cpe4":"cisco","cpe5":"unity_server","cpe6":"2.3","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2004","cve_id":"1322","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"h","cpe4":"cisco","cpe5":"unity_server","cpe6":"2.4","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2004","cve_id":"1322","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"h","cpe4":"cisco","cpe5":"unity_server","cpe6":"2.46","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2004","cve_id":"1322","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"h","cpe4":"cisco","cpe5":"unity_server","cpe6":"3.0","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2004","cve_id":"1322","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"h","cpe4":"cisco","cpe5":"unity_server","cpe6":"3.1","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2004","cve_id":"1322","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"h","cpe4":"cisco","cpe5":"unity_server","cpe6":"3.2","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2004","cve_id":"1322","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"h","cpe4":"cisco","cpe5":"unity_server","cpe6":"3.3","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2004","cve_id":"1322","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"h","cpe4":"cisco","cpe5":"unity_server","cpe6":"4.0","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-08T00:46:12.348Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"20041215 Cisco Unity Integrated with Exchange Has Default Passwords","tags":["vendor-advisory","x_refsource_CISCO","x_transferred"],"url":"http://www.cisco.com/warp/public/707/cisco-sa-20041215-unity.shtml"},{"name":"P-060","tags":["third-party-advisory","government-resource","x_refsource_CIAC","x_transferred"],"url":"http://www.ciac.org/ciac/bulletins/p-060.shtml"},{"name":"11954","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/11954"},{"name":"cisco-unity-exchange-default-accounts(18489)","tags":["vdb-entry","x_refsource_XF","x_transferred"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/18489"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2004-12-15T00:00:00.000Z","descriptions":[{"lang":"en","value":"Cisco Unity 2.x, 3.x, and 4.x, when integrated with Microsoft Exchange, has several hard coded usernames and passwords, which allows remote attackers to gain unauthorized access and change configuration settings or read outgoing or incoming e-mail messages."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2017-07-10T14:57:01.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"name":"20041215 Cisco Unity Integrated with Exchange Has Default Passwords","tags":["vendor-advisory","x_refsource_CISCO"],"url":"http://www.cisco.com/warp/public/707/cisco-sa-20041215-unity.shtml"},{"name":"P-060","tags":["third-party-advisory","government-resource","x_refsource_CIAC"],"url":"http://www.ciac.org/ciac/bulletins/p-060.shtml"},{"name":"11954","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/11954"},{"name":"cisco-unity-exchange-default-accounts(18489)","tags":["vdb-entry","x_refsource_XF"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/18489"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2004-1322","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Cisco Unity 2.x, 3.x, and 4.x, when integrated with Microsoft Exchange, has several hard coded usernames and passwords, which allows remote attackers to gain unauthorized access and change configuration settings or read outgoing or incoming e-mail messages."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"20041215 Cisco Unity Integrated with Exchange Has Default Passwords","refsource":"CISCO","url":"http://www.cisco.com/warp/public/707/cisco-sa-20041215-unity.shtml"},{"name":"P-060","refsource":"CIAC","url":"http://www.ciac.org/ciac/bulletins/p-060.shtml"},{"name":"11954","refsource":"BID","url":"http://www.securityfocus.com/bid/11954"},{"name":"cisco-unity-exchange-default-accounts(18489)","refsource":"XF","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/18489"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2004-1322","datePublished":"2005-01-06T05:00:00.000Z","dateReserved":"2005-01-06T00:00:00.000Z","dateUpdated":"2024-08-08T00:46:12.348Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2004-12-15 05:00:00","lastModifiedDate":"2025-04-03 01:03:51","problem_types":["NVD-CWE-Other","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:P/A:P","baseScore":7.5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"},"baseSeverity":"HIGH","exploitabilityScore":10,"impactScore":6.4,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":true,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:h:cisco:unity_server:2.0:*:*:*:*:*:*:*","matchCriteriaId":"A6659C2E-691B-47B8-9659-73FF4DEE3C19"},{"vulnerable":true,"criteria":"cpe:2.3:h:cisco:unity_server:2.1:*:*:*:*:*:*:*","matchCriteriaId":"C0317B33-20DC-4E57-8AFC-097FBC6067F4"},{"vulnerable":true,"criteria":"cpe:2.3:h:cisco:unity_server:2.2:*:*:*:*:*:*:*","matchCriteriaId":"D382C84D-C8F7-4257-B6C6-D00C595F6B63"},{"vulnerable":true,"criteria":"cpe:2.3:h:cisco:unity_server:2.3:*:*:*:*:*:*:*","matchCriteriaId":"6DF21240-6275-434F-B7C3-8CC029B9ABA2"},{"vulnerable":true,"criteria":"cpe:2.3:h:cisco:unity_server:2.4:*:*:*:*:*:*:*","matchCriteriaId":"8934A49D-9ABB-4B49-9B69-615B8CFFAF10"},{"vulnerable":true,"criteria":"cpe:2.3:h:cisco:unity_server:2.46:*:*:*:*:*:*:*","matchCriteriaId":"0E60BDFE-108B-4621-9B02-774AA844407B"},{"vulnerable":true,"criteria":"cpe:2.3:h:cisco:unity_server:3.0:*:*:*:*:*:*:*","matchCriteriaId":"856D99BB-1CB3-4A8D-9752-CC854829C65A"},{"vulnerable":true,"criteria":"cpe:2.3:h:cisco:unity_server:3.1:*:*:*:*:*:*:*","matchCriteriaId":"B13E26E7-8284-4B70-B51C-B3B96995094F"},{"vulnerable":true,"criteria":"cpe:2.3:h:cisco:unity_server:3.2:*:*:*:*:*:*:*","matchCriteriaId":"2414F807-1EAE-438D-9497-B6259AC1AA2C"},{"vulnerable":true,"criteria":"cpe:2.3:h:cisco:unity_server:3.3:*:*:*:*:*:*:*","matchCriteriaId":"CCB4D983-658F-4B5F-B136-02A9605DAF4C"},{"vulnerable":true,"criteria":"cpe:2.3:h:cisco:unity_server:4.0:*:*:*:*:*:*:*","matchCriteriaId":"D26F84D4-B6AC-4BAD-8D9D-B33842FEF9F9"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2004","CveId":"1322","Ordinal":"1","Title":"CVE-2004-1322","CVE":"CVE-2004-1322","Year":"2004"},"notes":[{"CveYear":"2004","CveId":"1322","Ordinal":"1","NoteData":"Cisco Unity 2.x, 3.x, and 4.x, when integrated with Microsoft Exchange, has several hard coded usernames and passwords, which allows remote attackers to gain unauthorized access and change configuration settings or read outgoing or incoming e-mail messages.","Type":"Description","Title":"CVE-2004-1322"},{"CveYear":"2004","CveId":"1322","Ordinal":"2","NoteData":"2005-01-06","Type":"Other","Title":"Published"},{"CveYear":"2004","CveId":"1322","Ordinal":"3","NoteData":"2017-07-10","Type":"Other","Title":"Modified"}]}}}