Описание
Cisco Personal Assistant 1.4(1) and 1.4(2) disables password authentication when "Allow Only Cisco CallManager Users" is enabled and the Corporate Directory settings refer to the directory service being used by Cisco CallManager, which allows remote attackers to gain access with a valid username.
Ссылки
- PatchVendor Advisory
- PatchVendor Advisory
Уязвимые конфигурации
Конфигурация 1
Одно из
cpe:2.3:a:cisco:personal_assistant:1.4\(1\):*:*:*:*:*:*:*
cpe:2.3:a:cisco:personal_assistant:1.4\(2\):*:*:*:*:*:*:*
EPSS
Процентиль: 75%
0.00883
Низкий
7.5 High
CVSS2
Дефекты
NVD-CWE-Other
Связанные уязвимости
github
больше 3 лет назад
Cisco Personal Assistant 1.4(1) and 1.4(2) disables password authentication when "Allow Only Cisco CallManager Users" is enabled and the Corporate Directory settings refer to the directory service being used by Cisco CallManager, which allows remote attackers to gain access with a valid username.
EPSS
Процентиль: 75%
0.00883
Низкий
7.5 High
CVSS2
Дефекты
NVD-CWE-Other