The Telnet service for Polycom ViewStation before 7.2.4 does not restrict the number of failed login attempts, which makes it easier for remote attackers to guess usernames and passwords via a brute force attack.
References
Link | Resource |
---|---|
http://bvlive01.iss.net/issEn/delivery/xforce/alertdetail.jsp?oid=21089 | Broken Link |
http://www.ciac.org/ciac/bulletins/m-123.shtml | Broken Link Patch Vendor Advisory |
http://www.iss.net/security_center/static/9349.php | Broken Link Vendor Advisory |
http://www.polycom.com/common/pw_item_show_doc/0%2C%2C1444%2C00.pdf | Product |
http://www.securityfocus.com/bid/5635 | Broken Link Third Party Advisory VDB Entry Vendor Advisory |
https://exchange.xforce.ibmcloud.com/vulnerabilities/44241 | Third Party Advisory VDB Entry |
Configurations
Configuration 1 (hide)
|
History
No history.
Information
Published : 2003-01-07 05:00
Updated : 2024-02-09 03:14
NVD link : CVE-2002-0628
Mitre link : CVE-2002-0628
CVE.ORG link : CVE-2002-0628
JSON object : View
Products Affected
polycom
- viewstation_512
- viewstation_dcp
- viewstation_v.35
- viewstation_mp
- viewstation_sp_384
- viewstation_h.323
- viewstation_128
- viewstation_fx_vs4000
CWE
CWE-307
Improper Restriction of Excessive Authentication Attempts