Cisco Ip Phone vulnerabilities
2 known vulnerabilities affecting cisco/cisco_ip_phone.
Total CVEs
2
CISA KEV
1
actively exploited
Public exploits
1
Exploited in wild
1
Severity breakdown
CRITICAL1HIGH1
Vulnerabilities
Page 1 of 1
CVE-2020-3161CRITICALCVSS 9.8KEVPoCvn/a2020-04-15
CVE-2020-3161 [CRITICAL] CWE-20 CVE-2020-3161: A vulnerability in the web server for Cisco IP Phones could allow an unauthenticated, remote attacke
A vulnerability in the web server for Cisco IP Phones could allow an unauthenticated, remote attacker to execute code with root privileges or cause a reload of an affected IP phone, resulting in a denial of service (DoS) condition. The vulnerability is due to a lack of proper input validation of HTTP requests. An attacker could exploit this vulnerabi
cvelistv5nvd
CVE-2020-3111HIGHCVSS 8.8≥ unspecified, < 12.7(1)2020-02-05
CVE-2020-3111 [HIGH] CWE-20 CVE-2020-3111: A vulnerability in the Cisco Discovery Protocol implementation for the Cisco IP Phone could allow an
A vulnerability in the Cisco Discovery Protocol implementation for the Cisco IP Phone could allow an unauthenticated, adjacent attacker to remotely execute code with root privileges or cause a reload of an affected IP phone. The vulnerability is due to missing checks when processing Cisco Discovery Protocol messages. An attacker could exploit this vulner
cvelistv5nvd