← לוח פגיעויות

CVE-2020-3161

קריטית 9.8 מנוצלת בשטח (KEV)

ניצול פעיל מאומת — קטלוג CISA KEV

שם
Cisco IP Phones Web Server Remote Code Execution and Denial-of-Service Vulnerability
נוסף לקטלוג
יעד טיפול (פדרלי)
פעולה נדרשת
Apply updates per vendor instructions.

תיאור (מקור, אנגלית)

A vulnerability in the web server for Cisco IP Phones could allow an unauthenticated, remote attacker to execute code with root privileges or cause a reload of an affected IP phone, resulting in a denial of service (DoS) condition. The vulnerability is due to a lack of proper input validation of HTTP requests. An attacker could exploit this vulnerability by sending a crafted HTTP request to the web server of a targeted device. A successful exploit could allow the attacker to remotely execute code with root privileges or cause a reload of an affected IP phone, resulting in a DoS condition.

מדדים

CVSS 3.1
9.8 (CRITICAL) מקור הציון: NVD CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS — סבירות ניצול
84% (אחוזון 100) נכון ל-30/7/2026
CWE
CWE-20

מוצרים מושפעים

cisco: ip phone 8865 firmware; cisco: ip phone 8865; cisco: ip phone 8851 firmware; cisco: ip phone 8851; cisco: ip phone 7841 firmware; cisco: ip phone 7841; cisco: ip phone 7821 firmware; cisco: ip phone 7821; cisco: ip phone 8811 firmware; cisco: ip phone 8811; cisco: ip phone 8861 firmware; cisco: ip phone 8861; cisco: ip phone 8845 firmware; cisco: ip phone 8845; cisco: ip phone 7861 firmware

קישורים