CVE-2020-3161
published 2020-04-15CVE-2020-3161: A vulnerability in the web server for Cisco IP Phones could allow an unauthenticated, remote attacker to execute code with root privileges or cause a reload of…
PriorityP195critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
KEVITWEXPLOIT
CISA Known Exploited Vulnerabilitydue 2022-05-03
Exploited in the wild
EPSS
83.73%
99.7th percentile
A vulnerability in the web server for Cisco IP Phones could allow an unauthenticated, remote attacker to execute code with root privileges or cause a reload of an affected IP phone, resulting in a denial of service (DoS) condition. The vulnerability is due to a lack of proper input validation of HTTP requests. An attacker could exploit this vulnerability by sending a crafted HTTP request to the web server of a targeted device. A successful exploit could allow the attacker to remotely execute code with root privileges or cause a reload of an affected IP phone, resulting in a DoS condition.
Affected
33 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | 8831_firmware | — | — |
| cisco | 8831_firmware | — | — |
| cisco | 8831_firmware | — | — |
| cisco | cisco_ip_phone | — | — |
| cisco | ip_phone_7811_firmware | — | — |
| cisco | ip_phone_7821_firmware | — | — |
| cisco | ip_phone_7841_firmware | — | — |
| cisco | ip_phone_7861_firmware | — | — |
| cisco | ip_phone_8811_firmware | — | — |
| cisco | ip_phone_8811_firmware | — | — |
| cisco | ip_phone_8811_firmware | — | — |
| cisco | ip_phone_8821-ex_firmware | — | — |
| cisco | ip_phone_8821-ex_firmware | — | — |
| cisco | ip_phone_8821-ex_firmware | — | — |
| cisco | ip_phone_8821_firmware | — | — |
| cisco | ip_phone_8821_firmware | — | — |
| cisco | ip_phone_8821_firmware | — | — |
| cisco | ip_phone_8841_firmware | — | — |
| cisco | ip_phone_8841_firmware | — | — |
| cisco | ip_phone_8841_firmware | — | — |
| cisco | ip_phone_8845_firmware | — | — |
| cisco | ip_phone_8845_firmware | — | — |
| cisco | ip_phone_8845_firmware | — | — |
| cisco | ip_phone_8851_firmware | — | — |
| cisco | ip_phone_8851_firmware | — | — |
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv3.09.8CRITICALCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.010.0CRITICALAV:N/AC:L/Au:N/C:C/I:C/A:C
vulncheck9.8CRITICAL
cisa9.8CRITICAL
vendor_cisco9.8CRITICAL
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
CISA
Cisco IP Phones Web Server Remote Code Execution and Denial-of-Service Vulnerability
cisa·2021-11-03·CVSS 9.8
CVE-2020-3161 [CRITICAL] CWE-20 Cisco IP Phones Web Server Remote Code Execution and Denial-of-Service Vulnerability
Vulnerability: Cisco IP Phones Web Server Remote Code Execution and Denial-of-Service Vulnerability
Affected: Cisco Cisco IP Phones
Cisco IP Phones contain an improper input validation vulnerability for HTTP requests. Exploitation could allow an attacker to execute code remotely with root privileges or cause a denial-of-service (DoS) condition.
Required Action: Apply updates per vendor instructions.
Notes: https://nvd.nist.gov/vuln/detail/CVE-2020-3161
Remediation Due Date: 2022-05-03
Cisco
Cisco IP Phones Web Server Remote Code Execution and Denial of Service Vulnerability
vendor_cisco·2020-04-15·CVSS 9.8
CVE-2020-3161 [CRITICAL] CWE-20 Cisco IP Phones Web Server Remote Code Execution and Denial of Service Vulnerability
Cisco IP Phones Web Server Remote Code Execution and Denial of Service Vulnerability
A vulnerability in the web server for Cisco IP Phones could allow an unauthenticated, remote attacker to execute code with root privileges or cause a reload of an affected IP phone, resulting in a denial of service (DoS) condition.
The vulnerability is due to a lack of proper input validation of HTTP requests. An attacker could exploit this vulnerability by sending a crafted HTTP request to the web server of a targeted device. A successful exploit could allow the attacker to remotely execute code with root privileges or cause a reload of an affected IP phone, resulting in a DoS condition.
Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulne
Cisco
Cisco IP Phones Web Server Remote Code Execution and Denial of Service Vulnerability
vendor_cisco·CVSS 3.0
CVE-2020-3161 Cisco IP Phones Web Server Remote Code Execution and Denial of Service Vulnerability
CVE-2020-3161: Cisco IP Phones Web Server Remote Code Execution and Denial of Service Vulnerability
A vulnerability in the web server for Cisco IP Phones could allow an unauthenticated, remote attacker to execute code with root privileges or cause a reload of an affected IP phone, resulting in a denial of service (DoS) condition. The vulnerability is due to a lack of proper input validation of HTTP requests. An attacker could exploit this vulnerability by sending a crafted HTTP request to the web server of a targeted device. A successful exploit could allow the attacker to remotely execute code with root privileges or cause a reload of an affected IP phone, resulting in a DoS condition. Cisco has released software updates that address this vulnerability. There are no
CVSS: 3.0
CWE: CWE-20,
GHSA
GHSA-74vv-6p4c-8fhj: A vulnerability in the web server for Cisco IP Phones could allow an unauthenticated, remote attacker to execute code with root privileges or cause a
ghsa_unreviewed·2022-05-24
CVE-2020-3161 [HIGH] CWE-20 GHSA-74vv-6p4c-8fhj: A vulnerability in the web server for Cisco IP Phones could allow an unauthenticated, remote attacker to execute code with root privileges or cause a
A vulnerability in the web server for Cisco IP Phones could allow an unauthenticated, remote attacker to execute code with root privileges or cause a reload of an affected IP phone, resulting in a denial of service (DoS) condition. The vulnerability is due to a lack of proper input validation of HTTP requests. An attacker could exploit this vulnerability by sending a crafted HTTP request to the web server of a targeted device. A successful exploit could allow the attacker to remotely execute code with root privileges or cause a reload of an affected IP phone, resulting in a DoS condition.
VulnCheck
Cisco IP Phones Web Server Remote Code Execution and Denial-of-Service Vulnerability
vulncheck·2020·CVSS 9.8
CVE-2020-3161 [CRITICAL] CWE-20 Cisco IP Phones Web Server Remote Code Execution and Denial-of-Service Vulnerability
Cisco IP Phones Web Server Remote Code Execution and Denial-of-Service Vulnerability
Cisco IP Phones contain an improper input validation vulnerability for HTTP requests. Exploitation could allow an attacker to execute code remotely with root privileges or cause a denial-of-service (DoS) condition.
Affected: Cisco Cisco IP Phones
Required Action: Apply updates per vendor instructions.
Exploitation References: https://www.cisa.gov/sites/default/files/feeds/known_exploited_vulnerabilities.json
Exploit PoC: https://vulncheck.com/xdb/683ddbd88289
Remediation Due: 2022-05-03
Suricata
ET EXPLOIT Cisco IP Phones Web Server Vulnerability (CVE-2020-3161)
suricata·2021-10-28·CVSS 9.8
CVE-2020-3161 [CRITICAL] ET EXPLOIT Cisco IP Phones Web Server Vulnerability (CVE-2020-3161)
ET EXPLOIT Cisco IP Phones Web Server Vulnerability (CVE-2020-3161)
Rule: alert http any any -> [$HOME_NET,$HTTP_SERVERS] any (msg:"ET EXPLOIT Cisco IP Phones Web Server Vulnerability (CVE-2020-3161)"; flow:established,to_server; http.method; content:"GET"; http.uri; content:"/deviceconfig/setActivationCode?params="; nocase; fast_pattern; isdataat:150,relative; reference:url,github.com/tenable/poc/blob/master/cisco/ip_phone/cve_2020_3161.txt; reference:cve,2020-3161; classtype:attempted-admin; sid:2034277; rev:1; metadata:attack_target Server, created_at 2021_10_28, cve CVE_2020_3161, deployment Perimeter, deployment Internal, confidence High, signature_severity Major, tag Exploit, tag CISA_KEV, updated_at 2021_10_28, mitre_tactic_id TA0001, mitre_tactic_name Initial_Access, mitre_techniq
http://packetstormsecurity.com/files/157265/Cisco-IP-Phone-11.7-Denial-Of-Service.htmlhttps://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-voip-phones-rce-dos-rB6EeRXshttp://packetstormsecurity.com/files/157265/Cisco-IP-Phone-11.7-Denial-Of-Service.htmlhttps://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-voip-phones-rce-dos-rB6EeRXshttps://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2020-3161
2020-04-15
Published
2021-11-03
Added to CISA KEV
Exploited in the wild