Password Authentication Bypass in Cisco Personal Assistant by Cisco Systems
CVE-2004-0044
Currently unrated
Summary
A security vulnerability in Cisco Personal Assistant versions 1.4(1) and 1.4(2) allows remote attackers to bypass password authentication when 'Allow Only Cisco CallManager Users' is enabled. If the Corporate Directory settings refer to the directory service utilized by Cisco CallManager, attackers can gain unauthorized access with valid usernames, jeopardizing user data and security.
References
Timeline
Vulnerability published
Vulnerability Reserved