CVE-2004-1760

critical Cisco
CVSS v3 Base Score
10.0
AV:N/AC:L/Au:N/C:C/I:C/A:C
EPSS Score
10.1%
Exploitation probability in 30 days
Top 7% most likely to be exploited
Attack Characteristics
Attack Vector
Network
Attack Complexity
Low
Confidentiality
C
Integrity
C
Availability
C
Published: January 21, 2004 (8149 days ago)
Last Modified: April 16, 2026
Vendor: Cisco
Source: NVD

Description

The default installation of Cisco voice products, when running the IBM Director Agent on IBM servers before OS 2000.2.6, does not require authentication, which allows remote attackers to gain administrator privileges by connecting to TCP port 14247.

CWE

CWE-287

Affected Products

cisco emergency respondercisco ip call center express enhancedcisco ip call center express standardcisco ip interactive voice responsecisco personal assistantibm director agentcisco call managercisco internet service nodecisco conference connectionibm mcs-7815-1000

References