Vulnerabilities > Cisco > Video Surveillance SP ISP > 1.23.7

DATE CVE VULNERABILITY TITLE RISK
2007-09-06 CVE-2007-4747 Improper Authentication vulnerability in Cisco products
The telnet service in Cisco Video Surveillance IP Gateway Encoder/Decoder (Standalone and Module) firmware 1.8.1 and earlier, Video Surveillance SP/ISP Decoder Software firmware 1.11.0 and earlier, and the Video Surveillance SP/ISP firmware 1.23.7 and earlier does not require authentication, which allows remote attackers to perform administrative actions, aka CSCsj31729.
network
low complexity
cisco CWE-287
critical
10.0
2007-09-06 CVE-2007-4746 Permissions, Privileges, and Access Controls vulnerability in Cisco products
The Cisco Video Surveillance IP Gateway Encoder/Decoder (Standalone and Module) firmware 1.8.1 and earlier, Video Surveillance SP/ISP Decoder Software firmware 1.11.0 and earlier, and the Video Surveillance SP/ISP firmware 1.23.7 and earlier have default passwords for the sypixx and root user accounts, which allows remote attackers to perform administrative actions, aka CSCsj34681.
network
low complexity
cisco CWE-264
critical
9.0