CVE-2004-1322

Cisco Unity 2.x-4.x - Unauthenticated Hardcoded Credential Exposure

Title source: llm
STIX 2.1

Description

Cisco Unity 2.x, 3.x, and 4.x, when integrated with Microsoft Exchange, has several hard coded usernames and passwords, which allows remote attackers to gain unauthorized access and change configuration settings or read outgoing or incoming e-mail messages.

References (4)

Core 4
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/18489
Patch, Vendor Advisory vendor-advisory x_refsource_cisco
http://www.cisco.com/warp/public/707/cisco-sa-20041215-unity.shtml
Patch, Vendor Advisory third-party-advisory government-resource x_refsource_ciac
http://www.ciac.org/ciac/bulletins/p-060.shtml
Patch, Vendor Advisory vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/11954

Scores

EPSS 0.0245
EPSS Percentile 82.7%

Details

Status published
Products (11)
cisco/unity_server 2.0
cisco/unity_server 2.1
cisco/unity_server 2.2
cisco/unity_server 2.3
cisco/unity_server 2.4
cisco/unity_server 2.46
cisco/unity_server 3.0
cisco/unity_server 3.1
cisco/unity_server 3.2
cisco/unity_server 3.3
... and 1 more
Published Dec 15, 2004
Tracked Since Feb 18, 2026