Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2016-1421

Опубликовано: 10 июн. 2016
Источник: nvd
CVSS3: 7.5
CVSS2: 5
EPSS Низкий

Описание

A vulnerability in the web application for Cisco IP Phones could allow an unauthenticated, remote attacker to execute code with root privileges or cause a reload of an affected IP phone, resulting in a denial of service (DoS) condition. The vulnerability exists because the affected software fails to check the bounds of input data. An attacker could exploit this vulnerability by sending a crafted HTTP request to the web server of a targeted device. A successful exploit could allow the attacker to remotely execute code with root privileges or cause a reload of an affected IP phone, resulting in a DoS condition.

Уязвимые конфигурации

Конфигурация 1

Одновременно

cpe:2.3:h:cisco:ip_phone:*:*:*:*:*:*:*:*
cpe:2.3:o:cisco:ip_phone_8800_series_firmware:11.0\(1\):*:*:*:*:*:*:*

EPSS

Процентиль: 89%
0.04701
Низкий

7.5 High

CVSS3

5 Medium

CVSS2

Дефекты

CWE-119
CWE-119

Связанные уязвимости

CVSS3: 7.5
github
больше 3 лет назад

A vulnerability in the web application for Cisco IP Phones could allow an unauthenticated, remote attacker to execute code with root privileges or cause a reload of an affected IP phone, resulting in a denial of service (DoS) condition. The vulnerability exists because the affected software fails to check the bounds of input data. An attacker could exploit this vulnerability by sending a crafted HTTP request to the web server of a targeted device. A successful exploit could allow the attacker to remotely execute code with root privileges or cause a reload of an affected IP phone, resulting in a DoS condition.

EPSS

Процентиль: 89%
0.04701
Низкий

7.5 High

CVSS3

5 Medium

CVSS2

Дефекты

CWE-119
CWE-119