Critical Command Injection Bug on Cisco IP Phones
Summary
Multiple vulnerabilities in the web-based management interface of certain Cisco IP Phones could allow an unauthenticated, remote attacker to execute arbitrary code or cause a denial of service.
Threat Type
Vulnerability
Overview
Cisco has issued an advisory for certain models of its IP phone lineup due to vulnerabilities in the web-based management interface that could allow an unauthenticated, remote attacker to perform arbitrary code execution or cause a denial of service. Affected phones include