QID 730176

Date Published: 2021-09-02

QID 730176: Cisco IP Phones Web Server Remote Code Execution and Denial of Service Vulnerability (cisco-sa-voip-phones-rce-dos-rB6EeRXs)

A vulnerability in the web server for Cisco IP Phones could allow an unauthenticated, remote attacker to execute code with
root privileges or cause a reload of an affected IP phone, resulting in a denial of service (DoS) condition

Affected Products
This vulnerability affects the following Cisco products if they have web access enabled and are running a firmware
release earlier than the first fixed release for that device:
IP Phone 7811, 7821, 7841, and 7861 Desktop Phones
IP Phone 8811, 8841, 8845, 8851, 8861, and 8865 Desktop Phones
Unified IP Conference Phone 8831
Wireless IP Phone 8821 and 8821-EX

Note: Potential Detection as cannot confirm if Multiplatform Firmware is used.

QID Detection Logic(Unauthenticated):
The QID sends a get request on "CGI/Java/Serviceability?adapter=device.statistics.device" and checks for the vulnerable version in the response.

A successful exploit could allow the attacker to remotely execute code with root privileges or cause a reload of an affected IP phone, resulting in a DoS condition.

  • CVSS V3 rated as Critical - 9.8 severity.
  • CVSS V2 rated as Critical - 10 severity.
  • Solution

    Customers are advised to refer to cisco-sa-voip-phones-rce-dos-rB6EeRXs for more information.

    CVEs related to QID 730176

    Software Advisories
    Advisory ID Software Component Link
    cisco-sa-voip-phones-rce-dos-rB6EeRXs URL Logo tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-voip-phones-rce-dos-rB6EeRXs