peter bassill · operator
$ cve CVE-2020-3161 JSON

CVE-2020-3161 KEV EXPLOIT

9.8
CRITICAL · CVSS 3.1 · EPSS 83.9% (pctl 100)

Patch first

On CISA KEV — known exploited in the wild, due 2022-05-03.

Description

A vulnerability in the web server for Cisco IP Phones could allow an unauthenticated, remote attacker to execute code with root privileges or cause a reload of an affected IP phone, resulting in a denial of service (DoS) condition. The vulnerability is due to a lack of proper input validation of HTTP requests. An attacker could exploit this vulnerability by sending a crafted HTTP request to the web server of a targeted device. A successful exploit could allow the attacker to remotely execute code with root privileges or cause a reload of an affected IP phone, resulting in a DoS condition.

Scoring

CVSS9.8 (CRITICAL, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS83.86% — more likely to be exploited than 100% of all CVEs
WeaknessCWE-20
On CISA KEVyes — remediate by 2022-05-03
Public exploityes
Published2020-04-15
Last modified2026-06-17

CISA KEV

NameCisco IP Phones Web Server Remote Code Execution and Denial-of-Service Vulnerability
Added2021-11-03
Due2022-05-03
Vendor / productCisco / Cisco IP Phones
Ransomware usenone reported

Affected (26)

VendorProduct
cisco8831
cisco8831 firmware
ciscoip phone 7811
ciscoip phone 7811 firmware
ciscoip phone 7821
ciscoip phone 7821 firmware
ciscoip phone 7841
ciscoip phone 7841 firmware
ciscoip phone 7861
ciscoip phone 7861 firmware
ciscoip phone 8811
ciscoip phone 8811 firmware
ciscoip phone 8821
ciscoip phone 8821 firmware
ciscoip phone 8821-ex
ciscoip phone 8821-ex firmware
ciscoip phone 8841
ciscoip phone 8841 firmware
ciscoip phone 8845
ciscoip phone 8845 firmware
ciscoip phone 8851
ciscoip phone 8851 firmware
ciscoip phone 8861
ciscoip phone 8861 firmware
ciscoip phone 8865
ciscoip phone 8865 firmware

Public exploits

SourceTitleDate
exploit-dbCisco IP Phone 11.7 - Denial of service (PoC)2020-04-17

References

→ the Explorer  ·  watch your stack  ·  NVD