QID 730748

Date Published: 2023-03-08

QID 730748: Cisco IP Phone 6800, 7800 and 8800 Series Denial of Service (DoS) Vulnerability (cisco-sa-ip-phone-cmd-inj-KMFynVcP)

A vulnerability in the web-based management interface of Cisco IP Phone 6800, 7800, and 8800 Series Multiplatform Phones, as well as Cisco Unified IP Conference Phone 8831 and Unified IP Phone 7900 Series Phones, could allow an unauthenticated, remote attacker to cause an affected device to reload, resulting in a denial of service (DoS) condition.

Affected Products
This vulnerability affects the following Cisco products if they are running a vulnerable release of Cisco Multiplatform Firmware:
IP Phone 6800 Series with Multiplatform Firmware
IP Phone 7800 Series with Multiplatform Firmware
IP Phone 8800 Series with Multiplatform Firmware
Unified IP Conference Phone 8831
Unified IP Conference Phone 8831 with Multiplatform Firmware

QID Detection Logic(Unauthenticated):
The QID sends a get request on "CGI/Java/Serviceability?adapter=device.statistics.device" and checks for the vulnerable version in the response.

A successful exploit could allow the attacker to cause a DoS condition.

  • CVSS V3 rated as High - 7.5 severity.
  • CVSS V2 rated as High - 7.8 severity.
  • Solution

    Customers are advised to refer to cisco-sa-ip-phone-cmd-inj-KMFynVcP for more information.

    CVEs related to QID 730748

    Software Advisories
    Advisory ID Software Component Link
    cisco-sa-ip-phone-cmd-inj-KMFynVcP URL Logo sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ip-phone-cmd-inj-KMFynVcP