Polycom SoundPoint IP Phone Default Password

high Nessus Plugin ID 55403

Synopsis

The remote device is using default web configuration credentials.

Description

The remote Polycom SoundPoint IP phone is using default credentials to protect some of its configuration pages. A remote attacker could use this information to mount further attacks.

Solution

Configure the device to use chosen credentials rather than the default credentials.

Plugin Details

Severity: High

ID: 55403

File Name: polycom_soundpoint_httpd_default_admin_password.nasl

Version: 1.8

Type: remote

Family: CGI abuses

Published: 6/22/2011

Updated: 1/19/2021

Supported Sensors: Nessus

Risk Information

CVSS v2

Risk Factor: High

Base Score: 7.5

Vector: CVSS2#AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Information

CPE: cpe:/h:polycom:soundpoint_ip_650

Excluded KB Items: global_settings/supplied_logins_only