CVE-2020-3161 is a critical vulnerability in the web server of Cisco IP Phones, stemming from improper input validation of HTTP requests. An unauthenticated, remote attacker can exploit this to execute code with root privileges or cause a denial of service (DoS) by reloading the affected device. With a CVSS score of 9.8 (Critical) and an EPSS score indicating high exploitability, this vulnerability is easily exploitable over the network with low attack complexity and no user interaction required. It is actively exploited in the wild, with proof-of-concept code available on ExploitDB, and has garnered significant community attention and media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
10.3\(1\)es14CPE matchmatch criteria | cpe:2.3:o:cisco:ip_phone_8865_firmware:10.3\(1\)es14:*:*:*:*:*:*:* | ||
11.0\(1\)CPE matchmatch criteria | cpe:2.3:o:cisco:ip_phone_8865_firmware:11.0\(1\):*:*:*:*:*:*:* | ||
11.0\(5\)sr1CPE matchmatch criteria | cpe:2.3:o:cisco:ip_phone_8865_firmware:11.0\(5\)sr1:*:*:*:*:*:*:* | ||
10.3\(1\)es14CPE matchmatch criteria | cpe:2.3:o:cisco:ip_phone_8851_firmware:10.3\(1\)es14:*:*:*:*:*:*:* | ||
11.0\(1\)CPE matchmatch criteria | cpe:2.3:o:cisco:ip_phone_8851_firmware:11.0\(1\):*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Cisco IP Phones Web Server Multiple Vulnerabilities
Apr 15, 2020Cisco IP Phones Web Server Multiple Vulnerabilities
Apr 15, 2020Cisco IP Phones Web Server Multiple Vulnerabilities
Apr 15, 2020Cisco IP Phones Web Server Multiple Vulnerabilities
Apr 15, 2020Cisco IP Phones Web Server Multiple Vulnerabilities
Apr 15, 2020Cisco IP Phones Web Server Multiple Vulnerabilities
Apr 15, 2020