First published: Mon Jan 05 2004(Updated: )
Cisco Unity on IBM servers is shipped with default settings that should have been disabled by the manufacturer, which allows local or remote attackers to conduct unauthorized activities via (1) a "bubba" local user account, (2) an open TCP port 34571, or (3) when a local DHCP server is unavailable, a DHCP server on the manufacturer's test network.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Cisco Unity Express | ||
Cisco Unity Server |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2003-0983 has been classified with a medium severity rating due to the risk of unauthorized access and actions by attackers.
To fix CVE-2003-0983, disable the default 'bubba' local user account and restrict access to TCP port 34571.
CVE-2003-0983 affects Cisco Unity on IBM servers, specifically Cisco Unity Express and Cisco Unity Server.
Yes, CVE-2003-0983 can be exploited remotely due to an open TCP port and default account settings.
If you cannot disable the 'bubba' account for CVE-2003-0983, consider implementing stricter network access controls to mitigate the risk.