CVE-2020-3161
KEV PoC massUnauthenticated RCE/DoS in Cisco IP Phone Web Server
CISA: Cisco IP Phones Web Server Remote Code Execution and Denial-of-Service Vulnerability
CVE-2020-3161 is a critical (CVSS 9.8) input-validation flaw (CWE-20) in the web server of multiple Cisco IP Phone 7800 and 8800 series models, including the 7811, 7821, 7841, 7861, 8811, 8841, 8845, 8851, 8861, 8865, 8821 and 8821-EX. An unauthenticated remote attacker can trigger it simply by sending a crafted HTTP request to the web server of a targeted phone, with no credentials or user interaction required. A successful exploit allows the attacker to execute code with root privileges on the device or force a reload, causing a denial-of-service condition. Any organization running the listed Cisco IP phone models where the phone's web server is reachable over the network is affected. The flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2021-11-03, carries a very high EPSS score of 83.9% (100th percentile), and a public denial-of-service proof of concept targeting the 11.7 firmware is available.
What to do: Apply updated firmware for all listed 7800/8800 series models per Cisco's instructions, as required by the CISA KEV catalog. Until phones are patched, restrict or disable the phone web server and limit HTTP access to trusted management networks, and inventory your environment for these models to confirm none are exposed to untrusted users.
| Cisco IP Phone 7811 firmware | Firmware per Cisco advisory; no specific ranges provided in source data |
| Cisco IP Phone 7821 firmware | Firmware per Cisco advisory; no specific ranges provided in source data |
| Cisco IP Phone 7841 firmware | Firmware per Cisco advisory; no specific ranges provided in source data |
| Cisco IP Phone 7861 firmware | Firmware per Cisco advisory; no specific ranges provided in source data |
| Cisco IP Phone 8811 firmware | Firmware per Cisco advisory; no specific ranges provided in source data |
| Cisco IP Phone 8821 firmware | Firmware per Cisco advisory; no specific ranges provided in source data |
| Cisco IP Phone 8821-EX firmware | Firmware per Cisco advisory; no specific ranges provided in source data |
| Cisco IP Phone 8841 firmware | Firmware per Cisco advisory; no specific ranges provided in source data |
| Cisco IP Phone 8845 firmware | Firmware per Cisco advisory; no specific ranges provided in source data |
| Cisco IP Phone 8851 firmware | Firmware per Cisco advisory; no specific ranges provided in source data |
| Cisco IP Phone 8861 firmware | Firmware per Cisco advisory; no specific ranges provided in source data |
| Cisco IP Phone 8865 firmware | Firmware per Cisco advisory; no specific ranges provided in source data |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
A vulnerability in the web server for Cisco IP Phones could allow an unauthenticated, remote attacker to execute code with root privileges or cause a reload of an affected IP phone, resulting in a denial of service (DoS) condition. The vulnerability is due to a lack of proper input validation of HTTP requests. An attacker could exploit this vulnerability by sending a crafted HTTP request to the web server of a targeted device. A successful exploit could allow the attacker to remotely execute code with root privileges or cause a reload of an affected IP phone, resulting in a DoS condition.
- Affected
- Cisco Cisco IP Phones
- Required action
- Apply updates per vendor instructions.
- Due date
- Ransomware use
- Unknown
- Vendors
- cisco
- Products
- ip phone 8865 firmware, ip phone 8851 firmware, ip phone 7841 firmware, ip phone 7821 firmware, ip phone 8811 firmware, ip phone 8861 firmware, ip phone 8845 firmware, ip phone 7861 firmware, ip phone 8841 firmware, ip phone 7811 firmware, ip phone 8821 firmware, ip phone 8821-ex firmware
- Weakness
- CWE-20
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H