5
CVSSv2

CVE-2015-0604

Published: 07/02/2015 Updated: 08/09/2017
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:N/I:P/A:N

Vulnerability Summary

The web framework on Cisco Unified IP 9900 phones with firmware 9.4(.1) and previous versions allows remote malicious users to upload files to arbitrary locations on a phone's filesystem via crafted HTTP requests, aka Bug ID CSCup90424.

Vulnerable Product Search on Vulmon Subscribe to Product

cisco unified_ip_phones_9971_firmware 9.4\\(.1\\)

cisco unified_ip_phones_9951_firmware 9.4\\(.1\\)

Vendor Advisories

A vulnerability in the web framework of Cisco Unified IP Phone 9900 Series could allow an unauthenticated, remote attacker to upload arbitrary files to the phone The vulnerability is due to insufficient validation of HTTP requests An attacker could exploit this vulnerability by sending a crafted request to the server An exploit could allow the ...