CVE-2003-0983
Status: ModifiedHigh (7.5)—
Cisco Unity on IBM servers is shipped with default settings that should have been disabled by the manufacturer, which allows local or remote attackers to conduct unauthorized activities via (1) a "bubba" local user account, (2) an open TCP port 34571, or (3) when a local DHCP server is unavailable, a DHCP server on the manufacturer's test network.
CVSS
- Version: 2.0
- Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P
- Base score: 7.5
Exploitation probability (EPSS)
- Probability of exploitation in the next 30 days: 1.88%
- Percentile among all scored CVEs: 79
- Score date: 10/8/2026
EPSS (Exploit Prediction Scoring System, FIRST) estimates how likely a vulnerability is to be exploited in the wild within 30 days. It complements CVSS (impact) and CISA KEV (confirmed exploitation).
Affected technologies (2)
CWEs
- NVD-CWE-Other
References
Raw JSON (NVD)
Show
{
"id": "CVE-2003-0983",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 7.5,
"accessVector": "NETWORK",
"vectorString": "AV:N/AC:L/Au:N/C:P/I:P/A:P",
"authentication": "NONE",
"integrityImpact": "PARTIAL",
"accessComplexity": "LOW",
"availabilityImpact": "PARTIAL",
"confidentialityImpact": "PARTIAL"
},
"acInsufInfo": false,
"impactScore": 6.4,
"baseSeverity": "HIGH",
"obtainAllPrivilege": false,
"exploitabilityScore": 10,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": true,
"userInteractionRequired": false
}
]
},
"affected": [
{
"source": "cve@mitre.org",
"affectedData": [
{
"vendor": "n/a",
"product": "n/a",
"versions": [
{
"status": "affected",
"version": "n/a"
}
]
}
]
}
],
"published": "2004-01-05T05:00:00.000",
"references": [
{
"url": "http://www.cisco.com/warp/public/707/cisco-sa-20031210-unity.shtml",
"tags": [
"Patch",
"Vendor Advisory"
],
"source": "cve@mitre.org"
},
{
"url": "http://www.cisco.com/warp/public/707/cisco-sa-20031210-unity.shtml",
"tags": [
"Patch",
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "NVD-CWE-Other"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "Cisco Unity on IBM servers is shipped with default settings that should have been disabled by the manufacturer, which allows local or remote attackers to conduct unauthorized activities via (1) a \"bubba\" local user account, (2) an open TCP port 34571, or (3) when a local DHCP server is unavailable, a DHCP server on the manufacturer's test network."
},
{
"lang": "es",
"value": "Cisco Unitiy en servidores IBM es entregado con una configuración por defecto que debería haber sido deshabilitada por el fabricante, lo que permite a atacantes locales o remotos conducir actividades no autorizadas mediante \r\n\r\nuna cuenta de usuario \"bubba\" local, o \r\nun puerto TCP 34571 abierto, o \r\ncuando un servidor DHCP local no está disponible, un servidor DHCP en la red de prueba del fabricante."
}
],
"lastModified": "2026-06-16T22:03:17.380",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:cisco:80-7111-01_for_the_unity-svrx255-1a:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "EE5BFD5D-964B-4036-908F-64F3B43F8220"
},
{
"criteria": "cpe:2.3:h:cisco:80-7112-01_for_the_unity-svrx255-2a:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "47C52046-B9A6-4A8D-B8BA-2EC40D3893EE"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "cve@mitre.org"
}