QID 730742
Date Published: 2023-03-06
QID 730742: Cisco IP Phone 6800, 7800 and 8800 Arbitrary Code Execution Vulnerability (cisco-sa-ip-phone-cmd-inj-KMFynVcP)
Multiple vulnerabilities in the web-based management interface of certain Cisco IP Phones could allow an unauthenticated, remote attacker to execute arbitrary code or cause a denial of service (DoS) condition.
Affected Products
This vulnerability affects the following Cisco products if they are running a vulnerable release of Cisco Multiplatform Firmware:
IP Phone 6800 Series with Multiplatform Firmware
IP Phone 7800 Series with Multiplatform Firmware
IP Phone 8800 Series with Multiplatform Firmware
QID Detection Logic(Unauthenticated):
The QID sends a get request on "CGI/Java/Serviceability?adapter=device.statistics.device" and checks for the vulnerable version in the response.
Note: This QID not checks for Multiplatform Firmware hence set as practice.
A successful exploit could allow the attacker to execute arbitrary commands on the underlying operating system of an affected device.
Customers are advised to refer to cisco-sa-ip-phone-cmd-inj-KMFynVcP for more information.
- cisco-sa-ip-phone-cmd-inj-KMFynVcP -
sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ip-phone-cmd-inj-KMFynVcP
CVEs related to QID 730742
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| cisco-sa-ip-phone-cmd-inj-KMFynVcP |
|