First published: Fri Oct 11 2002(Updated: )
The default configuration of Cisco Unity 2.x and 3.x does not block international operator calls in the predefined restriction tables, which could allow authenticated users to place international calls using call forwarding.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Cisco Unity Server | =2.2 | |
Cisco Unity Server | =3.0 | |
Cisco Unity Server | =3.1 | |
Cisco Unity Server | =2.3 | |
Cisco Unity Server | =2.1 | |
Cisco Unity Server | =2.46 | |
Cisco Unity Server | =2.4 | |
Cisco Unity Server | =2.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2002-1189 is classified as a moderate severity vulnerability due to its potential for toll fraud.
To address CVE-2002-1189, modify the configuration of Cisco Unity to block international operator calls.
CVE-2002-1189 affects users of Cisco Unity versions 2.0 through 3.1 who have not applied proper restrictions.
The impact of CVE-2002-1189 includes unauthorized international calls being placed through the system.
While CVE-2002-1189 is older, it remains a concern for organizations still using affected versions of Cisco Unity without updates.