CVE-2004-1760

CRITICAL

The default installation of Cisco voice products, when running the IBM Director Agent on IBM servers before OS 2000.2.6, does not require authentication, which allows remote attackers to gain admin...

Affects 17 products across 2 vendors.

BCS7.86
CVSS 2.010.0
EPSS3.8%
Percentile89th
PatchPatched
CVSS Vector — Plain English Remotely exploitable over the network, low complexity.
CWE Weakness Definitions
CWE-287: Improper Authentication

Software does not prove or insufficiently proves that the user is who they claim to be.

Related Attack Patterns (CAPEC)
CAPEC-57 Utilizing REST's Trust in the System Resource to Obtain Sensitive Data
via CWE-287
CAPEC-633 Token Impersonation
via CWE-287
CAPEC-650 Upload a Web Shell to a Web Server
via CWE-287
CAPEC-194 Fake the Source of Data
via CWE-287
CAPEC-593 Session Hijacking
via CWE-287
Show all 10

Mapping is CWE-to-CAPEC per MITRE CAPEC 3.9.

◆ SAGE Intelligence — CITED Relevance Research Team

This vulnerability was disclosed in 2004. A critical vulnerability affects Cisco systems (CVE-2004-1760). No public exploit code is currently available. Isolate affected systems if patching is not feasible.

BSID: BS-2004-GLOBAL-008662-C • Model: rule-based-v1 • Confidence: MEDIUM

Is this CVE in your environment?

BreachSpider monitors your ICS/OT environment for vulnerabilities like this one. No agents or network access required. Free to start.

Check My Environment →
Frequently Asked Questions
What is CVE-2004-1760?
This vulnerability was disclosed in 2004. A critical vulnerability affects Cisco systems (CVE-2004-1760). No public exploit code is currently available. Isolate affected systems if patching is not feasible.
What is the CVSS score for CVE-2004-1760?
CVE-2004-1760 has CVSS 10.0 (Critical). Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C. EPSS: 3.8%.
Is CVE-2004-1760 actively exploited?
No confirmed active exploitation of CVE-2004-1760 as of 2026-05-30.
How do I remediate CVE-2004-1760?
Priority: MEDIUM. Advisory: http://secunia.com/advisories/10696 PSIRT: [email protected]
What systems are affected by CVE-2004-1760?
CVE-2004-1760 affects: Cisco, Cisco, Cisco, Cisco, Cisco, Cisco, Cisco, Cisco.
Vulnerability Details
CVE IDCVE-2004-1760
BSIDBS-2004-GLOBAL-008662-C BreachSpider Global ID
CVSS VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Published2004-01-21
Last Modified2026-04-16
ICS Relevance90%
Weakness (CWE)
Domains
NETWORK-INFRA
SourceNVD
Official Description

The default installation of Cisco voice products, when running the IBM Director Agent on IBM servers before OS 2000.2.6, does not require authentication, which allows remote attackers to gain administrator privileges by connecting to TCP port 14247.

Source: NIST NVD / MITRE CVE Database

Attack Vector Analysis — CITED Relevance

Vulnerability details: The default installation of Cisco voice products, when running the IBM Director Agent on IBM servers before OS 2000.2.6, does not require authentication, which allows remote attackers to gain administrator privileges by connecting to TCP port 14247. CVSS vector: AV:N/AC:L/Au:N/C:C/I:C/A:C.

Exploitation Likelihood: LOW

Affected Products
VendorProductFixed Version
Cisco Call Manager
Cisco Emergency Responder
Cisco Ip Call Center Express Enhanced
Cisco Ip Call Center Express Standard
Cisco Ip Interactive Voice Response
Cisco Personal Assistant
Cisco Internet Service Node
Cisco Conference Connection
Ibm Director Agent
Ibm X345
Ibm Mcs-7815-1000
Ibm Mcs-7815I-2.0
Ibm Mcs-7835I-2.4
Ibm Mcs-7835I-3.0
Ibm X330
Ibm X340
Ibm X342
Remediation
View Vendor Advisory →

Remediation Priority: MEDIUM

Vendor PSIRT: [email protected]
Threat Intelligence
● Threat Intelligence Validated: August 2026 | Threat Age: 8232 Days
CISA KEVNot in KEV catalog
Public ExploitNot confirmed
PoC CodeNot confirmed
SAGE Enrichment Record — provenance & audit hash
Modelrule-based-v1
ConfidenceMEDIUM
Enriched At2026-05-24
SHA-512 Audit Hash05050949e7fd8c38da9b7bf817583078b338a14b509e3c3292a9e92999d4ac9f9b6794a110b46d53dd030a0f7a9f2a8ded156bf9409bd5f2e1c3e6c299157938
Related CVEs affecting Cisco
CVE-2008-0529 10.0 Buffer overflow in the telnet server in Cisco Unified IP Phone 7906G, 7911G, ... CVE-2007-2036 10.0 The SNMP implementation in the Cisco Wireless LAN Controller (WLC) before 200... CVE-2011-2555 10.0 Cisco TelePresence Recording Server 1.7.2.x before 1.7.2.1 has a default pass... CVE-2009-0620 10.0 Cisco ACE Application Control Engine Module for Catalyst 6500 Switches and 76... CVE-1999-0775 10.0 Cisco Gigabit Switch routers running IOS allow remote attackers to forward un...
View all Cisco CVEs →

Critical Severity - Know Your Exposure

A CVSS 10.0 vulnerability in your ICS environment cannot wait. BreachSpider maps critical CVEs to your specific assets and tells you what to fix first.

Check Your Assets Free →