Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2007-1063


The SSH server in Cisco Unified IP Phone 7906G, 7911G, 7941G, 7961G, 7970G, and 7971G, with firmware 8.0(4)SR1 and earlier, uses a hard-coded username and password, which allows remote attackers to access the device.


Published

2007-02-22T01:28:00.000

Last Modified

2025-04-09T00:30:58.490

Status

Deferred

Source

[email protected]

Severity

CVSSv2: 10.0 (HIGH)

CVSSv2 Vector

AV:N/AC:L/Au:N/C:C/I:C/A:C

  • Access Vector: NETWORK
  • Access Complexity: LOW
  • Authentication: NONE
  • Confidentiality Impact: COMPLETE
  • Integrity Impact: COMPLETE
  • Availability Impact: COMPLETE
Exploitability Score

10.0

Impact Score

10.0

Weaknesses
  • Type: Primary
    CWE-798

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Operating System cisco unified_ip_phone_firmware_7906g 8.0\(4\) Yes
Hardware cisco unified_ip_phone_7906g - No
Operating System cisco unified_ip_phone_firmware_7911g 8.0\(4\) Yes
Hardware cisco unified_ip_phone_7911g - No
Operating System cisco unified_ip_phone_firmware_7941g 8.0\(4\) Yes
Hardware cisco unified_ip_phone_7941g - No
Operating System cisco unified_ip_phone_firmware_7961g 8.0\(4\) Yes
Hardware cisco unified_ip_phone_7961g - No
Operating System cisco unified_ip_phone_firmware_7970g 8.0\(4\) Yes
Hardware cisco unified_ip_phone_7970g - No
Operating System cisco unified_ip_phone_firmware_7971g 8.0\(4\) Yes
Hardware cisco unified_ip_phone_7971g - No

References