Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-8v48-phm3-pw95

Опубликовано: 05 янв. 2026
Источник: github
Github: Не прошло ревью
CVSS3: 5.3

Описание

A vulnerability in the directory permissions of Cisco Desk Phone 9800 Series, Cisco IP Phone 7800 and 8800 Series, and Cisco Video Phone 8875 could allow an unauthenticated, remote attacker to write arbitrary files on an affected device.

This vulnerability is due to a lack of proper authentication controls. An attacker could exploit this vulnerability by sending a crafted request to an affected device. A successful exploit could allow the attacker to perform arbitrary file writes to specific directories in the underlying operating system. Note: To exploit this vulnerability, Web Access must be enabled on the phone. Web Access is disabled by default.

A vulnerability in the directory permissions of Cisco Desk Phone 9800 Series, Cisco IP Phone 7800 and 8800 Series, and Cisco Video Phone 8875 could allow an unauthenticated, remote attacker to write arbitrary files on an affected device.

This vulnerability is due to a lack of proper authentication controls. An attacker could exploit this vulnerability by sending a crafted request to an affected device. A successful exploit could allow the attacker to perform arbitrary file writes to specific directories in the underlying operating system. Note: To exploit this vulnerability, Web Access must be enabled on the phone. Web Access is disabled by default.

EPSS

Процентиль: 28%
0.00353
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-284

Связанные уязвимости

CVSS3: 5.3
nvd
12 месяцев назад

A vulnerability in the directory permissions of Cisco Desk Phone 9800 Series, Cisco IP Phone 7800 and 8800 Series, and Cisco Video Phone 8875 could allow an unauthenticated, remote attacker to write arbitrary files on an affected device. This vulnerability is due to a lack of proper authentication controls. An attacker could exploit this vulnerability by sending a crafted request to an affected device. A successful exploit could allow the attacker to perform arbitrary file writes to specific directories in the underlying operating system. Note: To exploit this vulnerability, Web Access must be enabled on the phone. Web Access is disabled by default.

CVSS3: 5.3
fstec
12 месяцев назад

Уязвимость микропрограммного обеспечения Cisco SIP IP-телефонов Cisco Video Phone 8875, Desk Phone 9800 и IP Phone 7800, 8800 Series, связанная с ошибками разграничения доступа, позволяющая нарушителю получить доступ на запись произвольных файлов

EPSS

Процентиль: 28%
0.00353
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-284