CVE-2007-1072 describes a critical vulnerability in the command line interface (CLI) of several Cisco Unified IP Phone models, including the 7906G, 7911G, 7941G, 7961G, 7970G, and 7971G running firmware 8.0(4)SR1 and earlier. This flaw allows local users to escalate privileges or trigger a denial of service through unspecified means. With a CVSS score of 7.2, this vulnerability is highly severe, indicating a low attack complexity and the potential for complete compromise of confidentiality, integrity, and availability. While it can be leveraged remotely via CVE-2007-1063, there is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
8.0\(4\)CPE matchmatch criteria | cpe:2.3:o:cisco:unified_ip_phone_firmware_7906g:8.0\(4\):sr1:*:*:*:*:*:* | ||
8.0\(4\)CPE matchmatch criteria | cpe:2.3:o:cisco:unified_ip_phone_firmware_7911g:8.0\(4\):sr1:*:*:*:*:*:* | ||
8.0\(4\)CPE matchmatch criteria | cpe:2.3:o:cisco:unified_ip_phone_firmware_7941g:8.0\(4\):sr1:*:*:*:*:*:* | ||
8.0\(4\)CPE matchmatch criteria | cpe:2.3:o:cisco:unified_ip_phone_firmware_7961g:8.0\(4\):sr1:*:*:*:*:*:* | ||
8.0\(4\)CPE matchmatch criteria | cpe:2.3:o:cisco:unified_ip_phone_firmware_7970g:8.0\(4\):sr1:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:L/AC:L/Au:N/C:C/I:C/A:C
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.5 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.