CVE-2002-0881: Low severity cisco Voip Phone Cp-7940 vulnerability
Published Aug 31, 2002
·Updated
Cisco IP Phone (VoIP) models 7910, 7940, and 7960 use a default administrative password, which allows attackers with physical access to the phone to modify the configuration settings.
Affected Software
6 affected components
cisco Voip Phone Cp-7940=3.0
cisco Voip Phone Cp-7940=3.1
cisco Voip Phone Cp-7940=3.2
cisco Skinny Client Control Protocol Software=3.0
cisco Skinny Client Control Protocol Software=3.1
cisco Skinny Client Control Protocol Software=3.2
Remediation
Patch Available
Patch Available
Event History
Aug 31, 2002
CVE Published
via MITRE·08:00 AM
Data Sourced
via MITRE·08:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2002-0881?
CVE-2002-0881 is classified as a high-severity vulnerability due to the potential for unauthorized configuration access.
2
How do I fix CVE-2002-0881?
To resolve CVE-2002-0881, change the default administrative password on affected Cisco IP Phone models.
3
Which models are affected by CVE-2002-0881?
CVE-2002-0881 affects Cisco IP Phone models 7910, 7940, and 7960 that use firmware versions 3.0, 3.1, and 3.2.
4
What attack vector is used in CVE-2002-0881?
CVE-2002-0881 allows attackers with physical access to a Cisco IP Phone to modify the configuration settings.
5
Is CVE-2002-0881 still a risk today?
CVE-2002-0881 remains a risk if devices are still in use with default passwords and physical access is not controlled.