ID

VAR-200210-0053


CVE

CVE-2002-1190


TITLE

Cisco Unity Use the recognized default user account vulnerability

Trust: 0.6

sources: CNNVD: CNNVD-200210-300

DESCRIPTION

Cisco Unity 2.x and 3.x uses well-known default user accounts, which could allow remote attackers to gain access and place arbitrary calls. Unity Server is prone to a remote security vulnerability

Trust: 1.26

sources: NVD: CVE-2002-1190 // BID: 89579 // VULHUB: VHN-5575

AFFECTED PRODUCTS

vendor:ciscomodel:unity serverscope:eqversion:3.1

Trust: 1.9

vendor:ciscomodel:unity serverscope:eqversion:3.0

Trust: 1.9

vendor:ciscomodel:unity serverscope:eqversion:2.46

Trust: 1.9

vendor:ciscomodel:unity serverscope:eqversion:2.4

Trust: 1.9

vendor:ciscomodel:unity serverscope:eqversion:2.3

Trust: 1.9

vendor:ciscomodel:unity serverscope:eqversion:2.2

Trust: 1.9

vendor:ciscomodel:unity serverscope:eqversion:2.1

Trust: 1.9

vendor:ciscomodel:unity serverscope:eqversion:2.0

Trust: 1.9

sources: BID: 89579 // CNNVD: CNNVD-200210-300 // NVD: CVE-2002-1190

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2002-1190
value: HIGH

Trust: 1.0

CNNVD: CNNVD-200210-300
value: HIGH

Trust: 0.6

VULHUB: VHN-5575
value: HIGH

Trust: 0.1

nvd@nist.gov: CVE-2002-1190
severity: HIGH
baseScore: 7.5
vectorString: AV:N/AC:L/AU:N/C:P/I:P/A:P
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: PARTIAL
availabilityImpact: PARTIAL
exploitabilityScore: 10.0
impactScore: 6.4
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.0

VULHUB: VHN-5575
severity: HIGH
baseScore: 7.5
vectorString: AV:N/AC:L/AU:N/C:P/I:P/A:P
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: PARTIAL
availabilityImpact: PARTIAL
exploitabilityScore: 10.0
impactScore: 6.4
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.1

sources: VULHUB: VHN-5575 // CNNVD: CNNVD-200210-300 // NVD: CVE-2002-1190

PROBLEMTYPE DATA

problemtype:NVD-CWE-Other

Trust: 1.0

sources: NVD: CVE-2002-1190

THREAT TYPE

remote

Trust: 0.6

sources: CNNVD: CNNVD-200210-300

TYPE

unknown

Trust: 0.6

sources: CNNVD: CNNVD-200210-300

EXTERNAL IDS

db:NVDid:CVE-2002-1190

Trust: 2.0

db:XFid:44545

Trust: 0.9

db:CNNVDid:CNNVD-200210-300

Trust: 0.7

db:XFid:10282

Trust: 0.6

db:CISCOid:20021004 PREDEFINED RESTRICTION TABLES ALLOW CALLS TO INTERNATIONAL OPERATOR

Trust: 0.6

db:BIDid:89579

Trust: 0.4

db:VULHUBid:VHN-5575

Trust: 0.1

sources: VULHUB: VHN-5575 // BID: 89579 // CNNVD: CNNVD-200210-300 // NVD: CVE-2002-1190

REFERENCES

url:http://www.cisco.com/warp/public/707/toll-fraud-pub.shtml

Trust: 2.0

url:http://www.iss.net/security_center/static/10282.php

Trust: 2.0

url:https://exchange.xforce.ibmcloud.com/vulnerabilities/44545

Trust: 1.1

url:http://xforce.iss.net/xforce/xfdb/44545

Trust: 0.9

sources: VULHUB: VHN-5575 // BID: 89579 // CNNVD: CNNVD-200210-300 // NVD: CVE-2002-1190

CREDITS

Unknown

Trust: 0.3

sources: BID: 89579

SOURCES

db:VULHUBid:VHN-5575
db:BIDid:89579
db:CNNVDid:CNNVD-200210-300
db:NVDid:CVE-2002-1190

LAST UPDATE DATE

2024-08-14T14:16:19.592000+00:00


SOURCES UPDATE DATE

db:VULHUBid:VHN-5575date:2017-07-11T00:00:00
db:BIDid:89579date:2002-10-28T00:00:00
db:CNNVDid:CNNVD-200210-300date:2005-10-20T00:00:00
db:NVDid:CVE-2002-1190date:2017-07-11T01:29:13.023

SOURCES RELEASE DATE

db:VULHUBid:VHN-5575date:2002-10-28T00:00:00
db:BIDid:89579date:2002-10-28T00:00:00
db:CNNVDid:CNNVD-200210-300date:2002-10-28T00:00:00
db:NVDid:CVE-2002-1190date:2002-10-28T05:00:00