First published: Thu Nov 24 2005(Updated: )
Cisco IP Phone (VoIP) 7920 1.0(8) contains certain hard-coded ("fixed") public and private SNMP community strings that cannot be changed, which allows remote attackers to obtain sensitive information.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Cisco Unified Wireless IP Phone 7920 Firmware | =1.0\(8\) | |
All of | ||
Cisco Unified Wireless IP Phone 7920 Firmware | =1.0\(8\) | |
Cisco 7920 Wireless IP Phone |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2005-3803 is classified as a medium severity vulnerability due to the risk of unauthorized access to sensitive information.
There is no direct fix for CVE-2005-3803 since the hard-coded SNMP community strings cannot be changed; consider implementing network segmentation or access controls to mitigate risks.
CVE-2005-3803 affects Cisco IP Phone 7920 running firmware version 1.0(8).
CVE-2005-3803 allows remote attackers to potentially obtain sensitive information through exploitation of the fixed SNMP community strings.
While no patch can be applied, users can limit exposure by restricting SNMP traffic to trusted networks and disabling SNMP if not needed.