CVE-2016-1421: Buffer Overflow
A vulnerability in the web application for Cisco IP Phones could allow an unauthenticated, remote attacker to execute code with root privileges or cause a reload of an affected IP phone, resulting in a denial of service (DoS) condition. The vulnerability exists because the affected software fails to check the bounds of input data. An attacker could exploit this vulnerability by sending a crafted HTTP request to the web server of a targeted device. A successful exploit could allow the attacker to remotely execute code with root privileges or cause a reload of an affected IP phone, resulting in a DoS condition.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2016-1421?
CVE-2016-1421 is considered a critical vulnerability due to its potential for remote code execution and denial of service.
How do I fix CVE-2016-1421?
To fix CVE-2016-1421, update your Cisco IP Phone 8800 Series firmware to version 11.0(2) or later.
What impact does CVE-2016-1421 have on affected devices?
CVE-2016-1421 can allow an unauthenticated attacker to execute arbitrary code with root privileges or cause a device reload, leading to service disruption.
Which devices are affected by CVE-2016-1421?
CVE-2016-1421 affects Cisco IP Phone 8800 Series devices running specific firmware versions.
Is CVE-2016-1421 a local or remote vulnerability?
CVE-2016-1421 is a remote vulnerability that can be exploited by an unauthenticated attacker over the network.