9.8
CVSSv3

CVE-2020-3161

Published: 15/04/2020 Updated: 12/08/2021
CVSS v2 Base Score: 10 | Impact Score: 10 | Exploitability Score: 10
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 890
Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Summary

A vulnerability in the web server for Cisco IP Phones could allow an unauthenticated, remote malicious user to execute code with root privileges or cause a reload of an affected IP phone, resulting in a denial of service (DoS) condition. The vulnerability is due to a lack of proper input validation of HTTP requests. An attacker could exploit this vulnerability by sending a crafted HTTP request to the web server of a targeted device. A successful exploit could allow the malicious user to remotely execute code with root privileges or cause a reload of an affected IP phone, resulting in a DoS condition.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

cisco ip phone 8865 firmware 10.3(1)es14

cisco ip phone 8865 firmware 11.0(1)

cisco ip phone 8865 firmware 11.0(5)sr1

cisco ip phone 8851 firmware 10.3(1)es14

cisco ip phone 8851 firmware 11.0(1)

cisco ip phone 8851 firmware 11.0(5)sr1

cisco ip phone 7841 firmware 11.0(1)

cisco ip phone 7821 firmware 11.0(1)

cisco ip phone 8811 firmware 10.3(1)es14

cisco ip phone 8811 firmware 11.0(1)

cisco ip phone 8811 firmware 11.0(5)sr1

cisco ip phone 8861 firmware 10.3(1)es14

cisco ip phone 8861 firmware 11.0(1)

cisco ip phone 8861 firmware 11.0(5)sr1

cisco ip phone 8845 firmware 10.3(1)es14

cisco ip phone 8845 firmware 11.0(1)

cisco ip phone 8845 firmware 11.0(5)sr1

cisco ip phone 7861 firmware 11.0(1)

cisco ip phone 8841 firmware 10.3(1)es14

cisco ip phone 8841 firmware 11.0(1)

cisco ip phone 8841 firmware 11.0(5)sr1

cisco ip phone 7811 firmware 11.0(1)

cisco ip phone 8821 firmware 10.3(1)es14

cisco ip phone 8821 firmware 11.0(1)

cisco ip phone 8821 firmware 11.0(5)sr1

cisco ip phone 8821-ex firmware 10.3(1)es14

cisco ip phone 8821-ex firmware 11.0(1)

cisco ip phone 8821-ex firmware 11.0(5)sr1

cisco 8831 firmware 10.3(1)es14

cisco 8831 firmware 11.0(1)

cisco 8831 firmware 11.0(5)sr1

Vendor Advisories

A vulnerability in the web server for Cisco IP Phones could allow an unauthenticated, remote attacker to execute code with root privileges or cause a reload of an affected IP phone, resulting in a denial of service (DoS) condition The vulnerability is due to a lack of proper input validation of HTTP requests An attacker could exploit this vulnera ...

Exploits

Cisco IP Phone version 117 denial of service proof of concept exploit ...

Github Repositories

Cisco IP Phone 11.7 - Denial of Service (PoC)

CVE-2020-3161 Cisco IP Phone 117 - Denial of Service (PoC)