First published: Sat Feb 07 2015(Updated: )
The web framework on Cisco Unified IP 9900 phones with firmware 9.4(.1) and earlier allows remote attackers to upload files to arbitrary locations on a phone's filesystem via crafted HTTP requests, aka Bug ID CSCup90424.
Credit: ykramarz@cisco.com
Affected Software | Affected Version | How to fix |
---|---|---|
Cisco Unified IP Phone 9971 Firmware | =9.4\(.1\) | |
Cisco Unified IP Phone 9971 Firmware | ||
Cisco Unified IP Phone 9951 Firmware | =9.4\(.1\) | |
Cisco Unified IP Phone 9951 Firmware |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2015-0604 is considered to have a medium severity due to the risk of unauthorized file uploads.
To mitigate CVE-2015-0604, update the firmware of Cisco Unified IP 9900 phones to a version later than 9.4(1).
CVE-2015-0604 affects Cisco Unified IP Phones 9951 and 9971 running firmware version 9.4(1) or earlier.
CVE-2015-0604 allows remote attackers to upload files to arbitrary locations on the phone's filesystem.
CVE-2015-0604 was reported as Bug ID CSCup90424 by Cisco security teams.