CVE-2004-1760: Critical severity Cisco Emergency Responder vulnerability
The default installation of Cisco voice products, when running the IBM Director Agent on IBM servers before OS 2000.2.6, does not require authentication, which allows remote attackers to gain administrator privileges by connecting to TCP port 14247.
Affected Software
Remediation
Patch Available
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the security risk associated with CVE-2004-1760?
CVE-2004-1760 allows remote attackers to gain administrator privileges due to the lack of authentication on TCP port 14247 in Cisco voice products.
Which Cisco products are affected by CVE-2004-1760?
CVE-2004-1760 affects various versions of Cisco Personal Assistant, Cisco Call Manager, Cisco IP Interactive Voice Response, and Cisco IP Call Center Express among others.
How can I mitigate the risks associated with CVE-2004-1760?
To mitigate CVE-2004-1760, ensure that access to TCP port 14247 requires authentication or restrict access to this port.
What should I do if I am using a vulnerable product listed in CVE-2004-1760?
If using a vulnerable product listed in CVE-2004-1760, it is recommended to update to a secure version or apply the necessary patches provided by Cisco.
Is there a patch available for CVE-2004-1760?
Yes, Cisco releases patches to address CVE-2004-1760, and it's important to refer to the vendor's advisories for updates.