The SSH server in Cisco Unified IP Phone 7906G, 7911G, 7941G, 7961G, 7970G, and 7971G, with firmware 8.0(4)SR1 and earlier, uses a hard-coded username and password, which allows remote attackers to access the device.
2007-02-22T01:28:00.000
2025-04-09T00:30:58.490
Deferred
CVSSv2: 10.0 (HIGH)
AV:N/AC:L/Au:N/C:C/I:C/A:C
10.0
10.0
| Type | Vendor | Product | Version/Range | Vulnerable? |
|---|---|---|---|---|
| Operating System | cisco | unified_ip_phone_firmware_7906g | 8.0\(4\) | Yes |
| Hardware | cisco | unified_ip_phone_7906g | - | No |
| Operating System | cisco | unified_ip_phone_firmware_7911g | 8.0\(4\) | Yes |
| Hardware | cisco | unified_ip_phone_7911g | - | No |
| Operating System | cisco | unified_ip_phone_firmware_7941g | 8.0\(4\) | Yes |
| Hardware | cisco | unified_ip_phone_7941g | - | No |
| Operating System | cisco | unified_ip_phone_firmware_7961g | 8.0\(4\) | Yes |
| Hardware | cisco | unified_ip_phone_7961g | - | No |
| Operating System | cisco | unified_ip_phone_firmware_7970g | 8.0\(4\) | Yes |
| Hardware | cisco | unified_ip_phone_7970g | - | No |
| Operating System | cisco | unified_ip_phone_firmware_7971g | 8.0\(4\) | Yes |
| Hardware | cisco | unified_ip_phone_7971g | - | No |