CVE-2017-12305
Last modified
CVE-2017-12305 is a vulnerability of currently unknown severity. A vulnerability in the debug interface of Cisco IP Phone 8800 series could allow an authenticated, local attacker to execute arbitrary commands, aka Debug Shell Command Injection. The vulnerability is due to insufficient input validation. EPSS estimates a 0.84% chance of exploitation in the next 30 days.
Description
A vulnerability in the debug interface of Cisco IP Phone 8800 series could allow an authenticated, local attacker to execute arbitrary commands, aka Debug Shell Command Injection. The vulnerability is due to insufficient input validation. An attacker could exploit this vulnerability by authenticating to the device and submitting additional command input to the affected parameter in the debug shell. Cisco Bug IDs: CSCvf80034.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Cisco | Ip Phone 8800 Series Firmware | All versions |
References
- http://www.securityfocus.com/bid/101869Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1039829Third Party Advisory, VDB Entry
- http://www.securityfocus.com/bid/101869Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1039829Third Party Advisory, VDB Entry
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2017-12305?
How severe is CVE-2017-12305?
How do I fix CVE-2017-12305?
Are you affected by CVE-2017-12305?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
