First published: Thu Feb 22 2007(Updated: )
The Cisco Unified IP Conference Station 7935 3.2(15) and earlier, and Station 7936 3.3(12) and earlier does not properly handle administrator HTTP sessions, which allows remote attackers to bypass authentication controls via a direct URL request to the administrative HTTP interface for a limited time
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Cisco Unified IP Conference Phone 8831 | <=3.2\(15\) | |
Cisco Unified IP Conference Station 7935 | ||
Cisco Unified IP Conference Station 7936 | <=3.3\(12\) | |
Cisco Unified IP Conference Station 7936 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2007-1062 is classified as a medium severity vulnerability.
To fix CVE-2007-1062, upgrade to a firmware version later than 3.2(15) for the 7935 model and later than 3.3(12) for the 7936 model.
CVE-2007-1062 affects Cisco Unified IP Conference Stations 7935 with firmware versions up to 3.2(15) and 7936 with firmware versions up to 3.3(12).
CVE-2007-1062 allows remote attackers to bypass authentication controls via a direct URL request to the administrative HTTP interface.
Currently, the recommended course of action for CVE-2007-1062 is to upgrade the affected devices, as there are no effective workarounds to mitigate the issue.