The Cisco Unified IP Conference Station 7935 3.2(15) and earlier,...
Vulnerability Description
The Cisco Unified IP Conference Station 7935 3.2(15) and earlier, and Station 7936 3.3(12) and earlier does not properly handle administrator HTTP sessions, which allows remote attackers to bypass authentication controls via a direct URL request to the administrative HTTP interface for a limited time
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2007-1062
Credits & Attribution
No credits recorded in the NVD database.
References
- http://www.cisco.com/warp/public/707/cisco-air-20070221-phone.shtml
- http://www.cisco.com/warp/public/707/cisco-sa-20070221-phone.shtml
- http://secunia.com/advisories/24262
- http://securitytracker.com/id?1017680
- http://www.securityfocus.com/bid/22647
- http://osvdb.org/45245
- http://www.vupen.com/english/advisories/2007/0688
- https://exchange.xforce.ibmcloud.com/vulnerabilities/32623
More from cisco
View All →Affected Vendor
cisco
View all reports →Affected Software
Timeline
CVSS Vectors
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.