>> Cisco Unified IP Phone Default Account Unauthorized Access and Denial of Service Issue
Title : Cisco Unified IP Phone Default Account Unauthorized Access and Denial of Service Issue VUPEN ID : VUPEN/ADV-2007-0689 CVE ID : CVE-2007-1063
Rated as : Moderate Risk
Remotely Exploitable : Yes Locally Exploitable : Yes Release Date : 2007-02-21
Technical Description
A vulnerability has been identified in Cisco Unified IP Phone, which could be exploited by attackers to gain unauthorized access to a vulnerable device. This issue is due to a design error where a hard coded default user account (used for debugging purposes) with a default password is embedded into the device's firmware, which could be exploited by attackers to access the Command Line Interface (CLI) of a vulnerable IP phone (remotely via the SSH service or via the console serial port) and execute certain commands leading to the crash or complete compromise of an affected device.