PT-2018-8769 · Cisco · Cisco Ip Phone 7800+2
Published
2018-07-16
·
Updated
2019-10-09
·
CVE-2018-0341
CVSS v2.0
9.0
High
| Vector | AV:N/AC:L/Au:S/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Cisco IP Phone 6800, 7800, and 8800 Series with Multiplatform Firmware versions prior to 11.2(1)
Description
The issue is related to insufficient input validation in the web-based UI, allowing an authenticated, remote attacker to perform command injection and execute commands with the privileges of the web server. This can be achieved by including arbitrary shell commands in a specific
user input field.Recommendations
For versions prior to 11.2(1), update to version 11.2(1) or later to resolve the issue. As a temporary workaround, consider restricting access to the web-based UI to minimize the risk of exploitation. Avoid using arbitrary shell commands in user input fields until the issue is resolved.
Fix
OS Command Injection
Command Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Cisco Ip Phone 6800
Cisco Ip Phone 7800
Cisco Ip Phone 8800