CVE-2012-1417

UnknownEPSS 1.73%

Last modified

CVE-2012-1417 is a vulnerability of currently unknown severity. Multiple cross-site scripting (XSS) vulnerabilities in Local Phone book and Blacklist form in Yealink VOIP Phones allow remote authenticated users to inject arbitrary web script or HTML via the user field to cgi-bin/ConfigManApp.com.. EPSS estimates a 1.73% chance of exploitation in the next 30 days.

Description

Multiple cross-site scripting (XSS) vulnerabilities in Local Phone book and Blacklist form in Yealink VOIP Phones allow remote authenticated users to inject arbitrary web script or HTML via the user field to cgi-bin/ConfigManApp.com.

Metrics

EPSS Probability
1.73%

74.7th percentile

Probability of exploitation in the next 30 days. Learn more

Weakness Enumeration

Affected Software

VendorProductVersions
YealinkGigabit Color Ip Phone Sip-T32gAll versions
YealinkGigabit Color Ip Phone Sip-T38gAll versions
YealinkIp Phone Sip-T19pAll versions
YealinkIp Phone Sip-T20pAll versions
YealinkIp Phone Sip-T21pAll versions
YealinkIp Phone Sip-T22pAll versions
YealinkIp Phone Sip-T26pAll versions
YealinkIp Phone Sip-T28pAll versions
YealinkIp Video Phone Vp530All versions
YealinkUltra-Elegant Ip Phone Sip-T41pAll versions
YealinkUltra-Elegant Ip Phone Sip-T42gAll versions
YealinkUltra-Elegant Ip Phone Sip-T46gAll versions
YealinkUltra-Elegant Ip Phone Sip-T48gAll versions
YealinkW52pAll versions

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2012-1417?
Multiple cross-site scripting (XSS) vulnerabilities in Local Phone book and Blacklist form in Yealink VOIP Phones allow remote authenticated users to inject arbitrary web script or HTML via the user field to cgi-bin/ConfigManApp.com.
How severe is CVE-2012-1417?
Severity scoring for CVE-2012-1417 is pending analysis. The EPSS model estimates a 1.73% probability of exploitation in the next 30 days.
How do I fix CVE-2012-1417?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2012-1417?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST