CVE-2004-0044
Last modified
CVE-2004-0044 is a vulnerability of currently unknown severity. Cisco Personal Assistant 1.4(1) and 1.4(2) disables password authentication when "Allow Only Cisco CallManager Users" is enabled and the Corporate Directory settings refer to the directory service being used by Cisco CallManager, which allows remote attackers to gain access with a valid username.. EPSS estimates a 1.68% chance of exploitation in the next 30 days.
Description
Cisco Personal Assistant 1.4(1) and 1.4(2) disables password authentication when "Allow Only Cisco CallManager Users" is enabled and the Corporate Directory settings refer to the directory service being used by Cisco CallManager, which allows remote attackers to gain access with a valid username.
Metrics
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Cisco | Personal Assistant | 1.4\(1\) |
| Cisco | Personal Assistant | 1.4\(2\) |
References
- http://www.cisco.com/warp/public/707/cisco-sa-20040108-pa.shtmlPatch, Vendor Advisory
- http://www.cisco.com/warp/public/707/cisco-sa-20040108-pa.shtmlPatch, Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2004-0044?
How severe is CVE-2004-0044?
How do I fix CVE-2004-0044?
Are you affected by CVE-2004-0044?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
