First published: Thu Jun 23 2016(Updated: )
Cisco 8800 phones with software 11.0(1) do not properly enforce mounted-filesystem permissions, which allows local users to write to arbitrary files by leveraging shell access, aka Bug ID CSCuz03014.
Credit: ykramarz@cisco.com
Affected Software | Affected Version | How to fix |
---|---|---|
Cisco 8800 | ||
Cisco IP Phone 8800 Series Firmware | =11.0\(1\) |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-1435 has a medium severity rating due to its potential for local privilege escalation.
To fix CVE-2016-1435, update the Cisco IP Phone 8800 Series firmware to a version that addresses the vulnerability.
The potential impacts of CVE-2016-1435 include unauthorized access to sensitive files and possible manipulation of device settings.
CVE-2016-1435 affects users of the Cisco IP Phone 8800 series running firmware version 11.0(1).
CVE-2016-1435 is a local file permission vulnerability that allows users to write to arbitrary files on the device.