First published: Wed Mar 01 2023(Updated: )
Multiple vulnerabilities in the web-based management interface of certain Cisco IP Phones could allow an unauthenticated, remote attacker to execute arbitrary code or cause a denial of service (DoS) condition.For more information about these vulnerabilities, see the
Affected Software | Affected Version | How to fix |
---|---|---|
Cisco IP Phone 6800 | ||
Cisco IP Phone 7800 Series Firmware | ||
Cisco IP Phone 8800 key expansion module |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability cisco-sa-ip-phone-cmd-inj-KMFynVcP is classified as high severity due to its potential for remote code execution.
To mitigate the cisco-sa-ip-phone-cmd-inj-KMFynVcP vulnerability, ensure that affected Cisco IP Phones are updated to the latest firmware version provided by Cisco.
The cisco-sa-ip-phone-cmd-inj-KMFynVcP vulnerability affects Cisco IP Phone 6800, 7800, and 8800 Series models.
Yes, an unauthenticated remote attacker can exploit the cisco-sa-ip-phone-cmd-inj-KMFynVcP vulnerability.
An attacker can execute arbitrary code or cause a denial of service (DoS) condition through the cisco-sa-ip-phone-cmd-inj-KMFynVcP vulnerability.