PT-2017-12480 · Cisco · Cisco Ip Phone 8800 Series

Published

2017-11-16

·

Updated

2019-10-09

·

CVE-2017-12305

CVSS v2.0

7.2

High

VectorAV:L/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Cisco IP Phone 8800 series (affected versions not specified)
Description A vulnerability in the debug interface could allow an authenticated, local attacker to execute arbitrary commands due to insufficient input validation. An attacker could exploit this by authenticating to the device and submitting additional command input to the affected parameter in the debug shell.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

OS Command Injection

Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2017-12305

Affected Products

Cisco Ip Phone 8800 Series