>> Cisco Unified IP Conference Station Administrative Interface Security Bypass Vulnerability
Title : Cisco Unified IP Conference Station Administrative Interface Security Bypass Vulnerability VUPEN ID : VUPEN/ADV-2007-0688 CVE ID : CVE-2007-1062 - CVE-2007-1072
Rated as : Moderate Risk
Remotely Exploitable : Yes Locally Exploitable : Yes Release Date : 2007-02-21
Technical Description
A vulnerability has been identified in Cisco Unified IP Conference Station, which could be exploited by attackers to bypass security restrictions. This issue is due to a design error in the HTTP interface that caches the administrator's credentials even after the administrator logs out of the device, which could allow unauthenticated attackers to gain complete administrative access to a vulnerable device by accessing certain management URLs directly.