First published: Sat Jun 04 2016(Updated: )
CISCO IP 8800 phones with software 11.0.1 and earlier allow local users to gain privileges for OS command execution via crafted CLI commands, aka Bug ID CSCuz03005.
Credit: ykramarz@cisco.com
Affected Software | Affected Version | How to fix |
---|---|---|
Cisco IP Phone 8800 Series Firmware | =10.2\(1\) | |
Cisco IP Phone 8800 Series Firmware | =10.2\(2\) | |
Cisco IP Phone 8800 Series Firmware | =10.3 | |
Cisco IP Phone 8800 Series Firmware | =10.3\(2\) | |
Cisco IP Phone 8800 Series Firmware | =11.0\(1\) |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-1403 has a medium severity rating, allowing local users to execute OS commands with elevated privileges.
To mitigate CVE-2016-1403, upgrade your Cisco IP Phone 8800 Series firmware to version 11.0.2 or later.
CVE-2016-1403 affects Cisco IP Phone 8800 Series firmware versions 10.2(1), 10.2(2), 10.3, 10.3(2), and 11.0(1).
CVE-2016-1403 requires local access, meaning it cannot be exploited remotely.
Any local user with access to the Cisco IP Phone 8800 can potentially exploit CVE-2016-1403.