CVE-2004-1760

UnknownEPSS 3.80%

Last modified

CVE-2004-1760 is a vulnerability of currently unknown severity. The default installation of Cisco voice products, when running the IBM Director Agent on IBM servers before OS 2000.2.6, does not require authentication, which allows remote attackers to gain administrator privileges by connecting to TCP port 14247.. EPSS estimates a 3.80% chance of exploitation in the next 30 days.

Description

The default installation of Cisco voice products, when running the IBM Director Agent on IBM servers before OS 2000.2.6, does not require authentication, which allows remote attackers to gain administrator privileges by connecting to TCP port 14247.

Metrics

EPSS Probability
3.80%

88.7th percentile

Probability of exploitation in the next 30 days. Learn more

Weakness Enumeration

Affected Software

VendorProductVersions
CiscoEmergency Responder1.1
CiscoIp Call Center Express Enhanced3.0
CiscoIp Call Center Express Standard3.0
CiscoIp Interactive Voice Response3.0
CiscoPersonal Assistant1.3\(1\)
CiscoPersonal Assistant1.3\(2\)
CiscoPersonal Assistant1.3\(3\)
CiscoPersonal Assistant1.3\(4\)
CiscoPersonal Assistant1.4\(1\)
CiscoPersonal Assistant1.4\(2\)
IbmDirector Agent2.2
IbmDirector Agent3.11
CiscoCall Manager1.0
CiscoCall Manager2.0
CiscoCall Manager3.0
CiscoCall Manager3.1
CiscoCall Manager3.1\(2\)
CiscoCall Manager3.1\(3a\)
CiscoCall Manager3.2
CiscoCall Manager3.3
CiscoCall Manager3.3\(3\)
CiscoCall Manager4.0
CiscoInternet Service NodeAll versions
CiscoConference Connection1.1\(1\)
CiscoConference Connection1.2
IbmMcs-7815-1000All versions
IbmMcs-7815i-2.0All versions
IbmMcs-7835i-2.4All versions
IbmMcs-7835i-3.0All versions
IbmX3308654
IbmX3308674
IbmX340All versions
IbmX342All versions
IbmX345All versions

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2004-1760?
The default installation of Cisco voice products, when running the IBM Director Agent on IBM servers before OS 2000.2.6, does not require authentication, which allows remote attackers to gain administrator privileges by connecting to TCP port 14247.
How severe is CVE-2004-1760?
Severity scoring for CVE-2004-1760 is pending analysis. The EPSS model estimates a 3.80% probability of exploitation in the next 30 days.
How do I fix CVE-2004-1760?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2004-1760?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST