CVE-2007-1063

Severity CVSS v4.0:
Pending analysis
Type:
CWE-798 Use of Hard-coded Credentials
Publication date:
22/02/2007
Last modified:
09/04/2025

Description

The SSH server in Cisco Unified IP Phone 7906G, 7911G, 7941G, 7961G, 7970G, and 7971G, with firmware 8.0(4)SR1 and earlier, uses a hard-coded username and password, which allows remote attackers to access the device.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:cisco:unified_ip_phone_firmware_7906g:8.0\(4\):sr1:*:*:*:*:*:*
cpe:2.3:h:cisco:unified_ip_phone_7906g:-:*:*:*:*:*:*:*
cpe:2.3:o:cisco:unified_ip_phone_firmware_7911g:8.0\(4\):sr1:*:*:*:*:*:*
cpe:2.3:h:cisco:unified_ip_phone_7911g:-:*:*:*:*:*:*:*
cpe:2.3:o:cisco:unified_ip_phone_firmware_7941g:8.0\(4\):sr1:*:*:*:*:*:*
cpe:2.3:h:cisco:unified_ip_phone_7941g:-:*:*:*:*:*:*:*
cpe:2.3:o:cisco:unified_ip_phone_firmware_7961g:8.0\(4\):sr1:*:*:*:*:*:*
cpe:2.3:h:cisco:unified_ip_phone_7961g:-:*:*:*:*:*:*:*
cpe:2.3:o:cisco:unified_ip_phone_firmware_7970g:8.0\(4\):sr1:*:*:*:*:*:*
cpe:2.3:h:cisco:unified_ip_phone_7970g:-:*:*:*:*:*:*:*
cpe:2.3:o:cisco:unified_ip_phone_firmware_7971g:8.0\(4\):sr1:*:*:*:*:*:*
cpe:2.3:h:cisco:unified_ip_phone_7971g:-:*:*:*:*:*:*:*