First published: Thu Jun 23 2016(Updated: )
The license-certificate upload functionality on Cisco 8800 phones with software 11.0(1) allows remote authenticated users to delete arbitrary files via an invalid file, aka Bug ID CSCuz03010.
Credit: ykramarz@cisco.com
Affected Software | Affected Version | How to fix |
---|---|---|
Cisco 8800 | ||
Cisco IP Phone 8800 Series Firmware | =11.0\(1\) |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-1434 is classified as a high severity vulnerability that allows remote authenticated users to delete arbitrary files.
To mitigate CVE-2016-1434, you should upgrade the Cisco IP Phone 8800 firmware to a version newer than 11.0(1).
CVE-2016-1434 affects Cisco 8800 phones running the 11.0(1) firmware version.
CVE-2016-1434 is a file deletion vulnerability stemming from improper validation of uploaded files.
Yes, CVE-2016-1434 can be exploited remotely by authenticated users who can upload invalid files.