CVE-2007-1063: Critical severity Cisco Unified Ip Phone Firmware 7906g vulnerability
The SSH server in Cisco Unified IP Phone 7906G, 7911G, 7941G, 7961G, 7970G, and 7971G, with firmware 8.0(4)SR1 and earlier, uses a hard-coded username and password, which allows remote attackers to access the device.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2007-1063?
CVE-2007-1063 is classified as a high severity vulnerability due to the use of hard-coded credentials in Cisco Unified IP Phones.
How do I fix CVE-2007-1063?
To mitigate CVE-2007-1063, upgrade the firmware of your affected Cisco Unified IP Phones to a version later than 8.0(4)SR1.
Which devices are affected by CVE-2007-1063?
CVE-2007-1063 affects Cisco Unified IP Phones 7906G, 7911G, 7941G, 7961G, 7970G, and 7971G with firmware 8.0(4)SR1 and earlier.
What risks are associated with CVE-2007-1063?
The vulnerability can allow remote attackers to gain unauthorized access to sensitive information and control the affected devices.
Is there a workaround for CVE-2007-1063?
The recommended workaround is to upgrade to a secure firmware version, as there are no effective configuration workarounds available for CVE-2007-1063.