CVE-2005-3723
Hitachi IP5000 VOIP WIFI Phone 1.5.6 does not allow the user to disable access to (1) SNMP or (2) TCP port 3390, which allows remote attackers to modify configuration using CVE-2005-3722, or access the Unidata Shell to obtain sensitive information or…
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (1.53%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Hitachi IP5000 VOIP WIFI Phone 1.5.6 does not allow the user to disable access to (1) SNMP or (2) TCP port 3390, which allows remote attackers to modify configuration using CVE-2005-3722, or access the Unidata Shell to obtain sensitive information or cause a denial of service.
- CVSS 2.0
- 7.5 HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
- EPSS
- 1.53% probability · 73th percentile
- CISA KEV
- Not listed
- Affected
- hitachi/ip5000 voip wifi phone
- Source
- cve@mitre.org
References
- http://marc.info/?l=full-disclosure&m=113217425618951&w=2
- http://secunia.com/advisories/17628Patch, Vendor Advisory
- http://www.hitachi-cable.co.jp/ICSFiles/infosystem/security/76659792_e.pdf
- http://marc.info/?l=full-disclosure&m=113217425618951&w=2
- http://secunia.com/advisories/17628Patch, Vendor Advisory
- http://www.hitachi-cable.co.jp/ICSFiles/infosystem/security/76659792_e.pdf
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.