9.8
CVSSv3

CVE-2020-3161

Published: 15/04/2020 Updated: 12/08/2021
CVSS v2 Base Score: 10 | Impact Score: 10 | Exploitability Score: 10
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 890
Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Summary

A vulnerability in the web server for Cisco IP Phones could allow an unauthenticated, remote malicious user to execute code with root privileges or cause a reload of an affected IP phone, resulting in a denial of service (DoS) condition. The vulnerability is due to a lack of proper input validation of HTTP requests. An attacker could exploit this vulnerability by sending a crafted HTTP request to the web server of a targeted device. A successful exploit could allow the malicious user to remotely execute code with root privileges or cause a reload of an affected IP phone, resulting in a DoS condition.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

cisco ip_phone_8865_firmware 10.3\\(1\\)es14

cisco ip_phone_8865_firmware 11.0\\(1\\)

cisco ip_phone_8865_firmware 11.0\\(5\\)sr1

cisco ip_phone_8851_firmware 10.3\\(1\\)es14

cisco ip_phone_8851_firmware 11.0\\(1\\)

cisco ip_phone_8851_firmware 11.0\\(5\\)sr1

cisco ip_phone_7841_firmware 11.0\\(1\\)

cisco ip_phone_7821_firmware 11.0\\(1\\)

cisco ip_phone_8811_firmware 10.3\\(1\\)es14

cisco ip_phone_8811_firmware 11.0\\(1\\)

cisco ip_phone_8811_firmware 11.0\\(5\\)sr1

cisco ip_phone_8861_firmware 10.3\\(1\\)es14

cisco ip_phone_8861_firmware 11.0\\(1\\)

cisco ip_phone_8861_firmware 11.0\\(5\\)sr1

cisco ip_phone_8845_firmware 10.3\\(1\\)es14

cisco ip_phone_8845_firmware 11.0\\(1\\)

cisco ip_phone_8845_firmware 11.0\\(5\\)sr1

cisco ip_phone_7861_firmware 11.0\\(1\\)

cisco ip_phone_8841_firmware 10.3\\(1\\)es14

cisco ip_phone_8841_firmware 11.0\\(1\\)

cisco ip_phone_8841_firmware 11.0\\(5\\)sr1

cisco ip_phone_7811_firmware 11.0\\(1\\)

cisco ip_phone_8821_firmware 10.3\\(1\\)es14

cisco ip_phone_8821_firmware 11.0\\(1\\)

cisco ip_phone_8821_firmware 11.0\\(5\\)sr1

cisco ip_phone_8821-ex_firmware 10.3\\(1\\)es14

cisco ip_phone_8821-ex_firmware 11.0\\(1\\)

cisco ip_phone_8821-ex_firmware 11.0\\(5\\)sr1

cisco 8831_firmware 10.3\\(1\\)es14

cisco 8831_firmware 11.0\\(1\\)

cisco 8831_firmware 11.0\\(5\\)sr1

Vendor Advisories

A vulnerability in the web server for Cisco IP Phones could allow an unauthenticated, remote attacker to execute code with root privileges or cause a reload of an affected IP phone, resulting in a denial of service (DoS) condition The vulnerability is due to a lack of proper input validation of HTTP requests An attacker could exploit this vulnera ...

Exploits

Cisco IP Phone version 117 denial of service proof of concept exploit ...

Github Repositories

Cisco IP Phone 11.7 - Denial of Service (PoC)

CVE-2020-3161 Cisco IP Phone 117 - Denial of Service (PoC)