CVE-2016-1421
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
A vulnerability in the web application for Cisco IP Phones could allow an unauthenticated, remote attacker to execute code with root privileges or cause a reload of an affected IP phone, resulting in a denial of service (DoS) condition. The vulnerability exists because the affected software fails to check the bounds of input data. An attacker could exploit this vulnerability by sending a crafted HTTP request to the web server of a targeted device. A successful exploit could allow the attacker to remotely execute code with root privileges or cause a reload of an affected IP phone, resulting in a DoS condition.
Una vulnerabilidad en la aplicación web para los teléfonos IP de Cisco podría permitir que un atacante remoto no autenticado ejecute código con privilegios de root o provoque una recarga de un teléfono IP afectado, resultando en una condición de denegación de servicio (DoS). La vulnerabilidad existe porque el software afectado no puede verificar los límites de los datos de entrada. Un atacante podría aprovechar esta vulnerabilidad enviando una solicitud HTTP especialmente diseñada al servidor web de un dispositivo objetivo. Una explotación con éxito podría permitir al atacante ejecutar código de forma remota con privilegios de root o causar una recarga de un teléfono IP afectado, lo que provocaría una condición DoS.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2016-01-04 CVE Reserved
- 2016-06-10 CVE Published
- 2024-07-10 EPSS Updated
- 2024-08-05 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer
CAPEC
References (3)
URL | Tag | Source |
---|---|---|
https://www.tenable.com/security/research/tra-2020-24 | X_refsource_misc |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Cisco Search vendor "Cisco" | Ip Phone 8800 Series Firmware Search vendor "Cisco" for product "Ip Phone 8800 Series Firmware" | 11.0\(1\) Search vendor "Cisco" for product "Ip Phone 8800 Series Firmware" and version "11.0\(1\)" | - |
Affected
| in | Cisco Search vendor "Cisco" | Ip Phone Search vendor "Cisco" for product "Ip Phone" | * | - |
Safe
|