First published: Fri Oct 11 2013(Updated: )
The image-upgrade functionality on Cisco 9900 Unified IP phones allows local users to gain privileges by placing shell commands in an unspecified parameter, aka Bug ID CSCuh10334.
Credit: ykramarz@cisco.com
Affected Software | Affected Version | How to fix |
---|---|---|
Cisco Unified IP Phone 9900 Series Firmware | ||
Cisco Unified IP Phone 9951 Firmware | ||
Cisco Unified IP Phone 9971 Firmware |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2013-5533 is considered a high severity vulnerability due to its potential for local privilege escalation.
To fix CVE-2013-5533, update your Cisco Unified IP Phone 9900 Series firmware to the latest version provided by Cisco.
CVE-2013-5533 affects Cisco Unified IP Phones 9951 and 9971 as well as the Cisco Unified IP Phone 9900 Series.
CVE-2013-5533 allows local users to execute arbitrary shell commands, potentially leading to unauthorized access or control of the device.
There are no specific workarounds recommended for CVE-2013-5533; updating the firmware is the primary mitigation method.