Cisco VoIP Phone Default Administrative Password Vulnerability
BID:4799
Info
Cisco VoIP Phone Default Administrative Password Vulnerability
| Bugtraq ID: | 4799 |
| Class: | Design Error |
| CVE: |
CVE-2002-0881 |
| Remote: | No |
| Local: | Yes |
| Published: | May 22 2002 12:00AM |
| Updated: | Jul 11 2009 12:46PM |
| Credit: | Vulnerability discovery credited to Johnathan Nightingale <[email protected]>. |
| Vulnerable: |
Cisco VoIP Phone CP-7960 3.2 Cisco VoIP Phone CP-7960 3.1 Cisco VoIP Phone CP-7960 3.0 Cisco VoIP Phone CP-7940 3.2 Cisco VoIP Phone CP-7940 3.1 Cisco VoIP Phone CP-7940 3.0 Cisco VoIP Phone CP-7910 3.2 Cisco VoIP Phone CP-7910 3.1 Cisco VoIP Phone CP-7910 3.0 |
| Not Vulnerable: | |
Discussion
Cisco VoIP Phone Default Administrative Password Vulnerability
The 7900 series VoIP Phones are a Voice-Over-IP solution distributed by Cisco Systems.
By default, Cisco VoIP 7900 series phones use a default administrative password. The firmware sets a hard coded password of asterisk-asterisk-pound (*-*-#) that allows a user access to phone configuration parameters in the firmware. Through the use of this password, a user with physical access to the phone may be able to change configuration information on the phone.
The 7900 series VoIP Phones are a Voice-Over-IP solution distributed by Cisco Systems.
By default, Cisco VoIP 7900 series phones use a default administrative password. The firmware sets a hard coded password of asterisk-asterisk-pound (*-*-#) that allows a user access to phone configuration parameters in the firmware. Through the use of this password, a user with physical access to the phone may be able to change configuration information on the phone.
Exploit / POC
Cisco VoIP Phone Default Administrative Password Vulnerability
No exploit is required for this vulnerability.
No exploit is required for this vulnerability.
References
Cisco VoIP Phone Default Administrative Password Vulnerability
References:
References: