Fixed Public and Private SNMP Community Strings in Cisco IP Phone 7920 by Cisco
CVE-2005-3803

7.5HIGH

Key Information:

Vendor
Cisco
Vendor
CVE Published:
24 November 2005

Summary

The Cisco IP Phone 7920 version 1.0(8) is impacted by a vulnerability due to hard-coded public and private SNMP community strings. These strings, which are fixed and cannot be modified, allow unauthorized remote attackers to gain access to sensitive information through SNMP queries, potentially compromising the confidentiality of the system.

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.