CVE-2016-1403: Input Validation
Published Jun 4, 2016
·Updated
CISCO IP 8800 phones with software 11.0.1 and earlier allow local users to gain privileges for OS command execution via crafted CLI commands, aka Bug ID CSCuz03005.
Affected Software
5 affected components
cisco Ip Phone 8800 Series Firmware=10.2\(1\)
cisco Ip Phone 8800 Series Firmware=10.2\(2\)
cisco Ip Phone 8800 Series Firmware=10.3
cisco Ip Phone 8800 Series Firmware=10.3\(2\)
cisco Ip Phone 8800 Series Firmware=11.0\(1\)
Event History
Jun 4, 2016
CVE Published
via MITRE·02:00 PM
Data Sourced
via MITRE·02:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2016-1403?
CVE-2016-1403 has a medium severity rating, allowing local users to execute OS commands with elevated privileges.
2
How do I fix CVE-2016-1403?
To mitigate CVE-2016-1403, upgrade your Cisco IP Phone 8800 Series firmware to version 11.0.2 or later.
3
What versions are affected by CVE-2016-1403?
CVE-2016-1403 affects Cisco IP Phone 8800 Series firmware versions 10.2(1), 10.2(2), 10.3, 10.3(2), and 11.0(1).
4
Can CVE-2016-1403 be exploited remotely?
CVE-2016-1403 requires local access, meaning it cannot be exploited remotely.
5
Who can exploit CVE-2016-1403?
Any local user with access to the Cisco IP Phone 8800 can potentially exploit CVE-2016-1403.