CVE-2020-3161
קריטית 9.8 מנוצלת בשטח (KEV)
ניצול פעיל מאומת — קטלוג CISA KEV
- שם
- Cisco IP Phones Web Server Remote Code Execution and Denial-of-Service Vulnerability
- נוסף לקטלוג
- יעד טיפול (פדרלי)
- פעולה נדרשת
- Apply updates per vendor instructions.
תיאור (מקור, אנגלית)
A vulnerability in the web server for Cisco IP Phones could allow an unauthenticated, remote attacker to execute code with root privileges or cause a reload of an affected IP phone, resulting in a denial of service (DoS) condition. The vulnerability is due to a lack of proper input validation of HTTP requests. An attacker could exploit this vulnerability by sending a crafted HTTP request to the web server of a targeted device. A successful exploit could allow the attacker to remotely execute code with root privileges or cause a reload of an affected IP phone, resulting in a DoS condition.
מדדים
- CVSS 3.1
-
9.8 (CRITICAL)
מקור הציון: NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H - EPSS — סבירות ניצול
- 84% (אחוזון 100) נכון ל-30/7/2026
- CWE
- CWE-20
מוצרים מושפעים
cisco: ip phone 8865 firmware; cisco: ip phone 8865; cisco: ip phone 8851 firmware; cisco: ip phone 8851; cisco: ip phone 7841 firmware; cisco: ip phone 7841; cisco: ip phone 7821 firmware; cisco: ip phone 7821; cisco: ip phone 8811 firmware; cisco: ip phone 8811; cisco: ip phone 8861 firmware; cisco: ip phone 8861; cisco: ip phone 8845 firmware; cisco: ip phone 8845; cisco: ip phone 7861 firmware
קישורים
- https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa… Vendor Advisory
- https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa… Vendor Advisory
- http://packetstormsecurity.com/files/157265/Cisco-IP-Phone-11.7-Denial-Of-Serv… ExploitThird Party AdvisoryVDB Entry
- http://packetstormsecurity.com/files/157265/Cisco-IP-Phone-11.7-Denial-Of-Serv… ExploitThird Party AdvisoryVDB Entry
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-202… US Government Resource