CVE-2021-34711: Cisco IP Phone Software Arbitrary File Read Vulnerability
A vulnerability in the debug shell of Cisco IP Phone software could allow an authenticated, local attacker to read any file on the device file system. This vulnerability is due to insufficient input validation. An attacker could exploit this vulnerability by providing crafted input to a debug shell command. A successful exploit could allow the attacker to read any file on the device file system.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2021-34711?
CVE-2021-34711 is a vulnerability in the debug shell of Cisco IP Phone software that allows an authenticated, local attacker to read any file on the device file system.
How does CVE-2021-34711 occur?
This vulnerability is due to insufficient input validation in the debug shell of Cisco IP Phone software.
What is the severity of CVE-2021-34711?
CVE-2021-34711 has a severity score of 5.5, which is considered medium.
Which Cisco IP Phone software versions are affected by CVE-2021-34711?
CVE-2021-34711 affects Cisco IP Conference Phone 7832 Firmware up to version 14.1(1), Cisco IP Conference Phone 8832 Firmware up to version 14.1(1), Cisco IP Phone 7811 Firmware up to version 14.1(1), Cisco IP Phone 7821 Firmware up to version 14.1(1), Cisco IP Phone 7832 Firmware up to version 14.1(1), Cisco IP Phone 7841 Firmware up to version 14.1(1), Cisco IP Phone 7861 Firmware up to version 14.1(1), Cisco IP Phone 8811 Firmware up to version 14.1(1), Cisco IP Phone 8831 Firmware up to version 14.1(1), Cisco IP Phones 8832 Firmware up to version 14.1(1), Cisco IP Phone 8841 Firmware up to version 14.1(1), Cisco IP Phone 8845 Firmware up to version 14.1(1), Cisco IP Phone 8851 Firmware up to version 14.1(1), Cisco IP Phone 8861 Firmware up to version 14.1(1), Cisco IP Phone 8865 Firmware up to version 14.1(1), and Cisco Wireless IP Phone 8821 Firmware up to version 11.0(6)sr2.
How can CVE-2021-34711 be fixed?
To fix CVE-2021-34711, Cisco recommends upgrading to a fixed software release.