ZeroHour

CVE-2020-3161

KEV PoC mass

Unauthenticated RCE/DoS in Cisco IP Phone Web Server

CISA: Cisco IP Phones Web Server Remote Code Execution and Denial-of-Service Vulnerability

CVSS 3.1
9.8 critical
EPSS
84%p100
Published
()
KEV added
AI analysis

CVE-2020-3161 is a critical (CVSS 9.8) input-validation flaw (CWE-20) in the web server of multiple Cisco IP Phone 7800 and 8800 series models, including the 7811, 7821, 7841, 7861, 8811, 8841, 8845, 8851, 8861, 8865, 8821 and 8821-EX. An unauthenticated remote attacker can trigger it simply by sending a crafted HTTP request to the web server of a targeted phone, with no credentials or user interaction required. A successful exploit allows the attacker to execute code with root privileges on the device or force a reload, causing a denial-of-service condition. Any organization running the listed Cisco IP phone models where the phone's web server is reachable over the network is affected. The flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2021-11-03, carries a very high EPSS score of 83.9% (100th percentile), and a public denial-of-service proof of concept targeting the 11.7 firmware is available.

What to do: Apply updated firmware for all listed 7800/8800 series models per Cisco's instructions, as required by the CISA KEV catalog. Until phones are patched, restrict or disable the phone web server and limit HTTP access to trusted management networks, and inventory your environment for these models to confirm none are exposed to untrusted users.

Affected
Cisco IP Phone 7811 firmwareFirmware per Cisco advisory; no specific ranges provided in source data
Cisco IP Phone 7821 firmwareFirmware per Cisco advisory; no specific ranges provided in source data
Cisco IP Phone 7841 firmwareFirmware per Cisco advisory; no specific ranges provided in source data
Cisco IP Phone 7861 firmwareFirmware per Cisco advisory; no specific ranges provided in source data
Cisco IP Phone 8811 firmwareFirmware per Cisco advisory; no specific ranges provided in source data
Cisco IP Phone 8821 firmwareFirmware per Cisco advisory; no specific ranges provided in source data
Cisco IP Phone 8821-EX firmwareFirmware per Cisco advisory; no specific ranges provided in source data
Cisco IP Phone 8841 firmwareFirmware per Cisco advisory; no specific ranges provided in source data
Cisco IP Phone 8845 firmwareFirmware per Cisco advisory; no specific ranges provided in source data
Cisco IP Phone 8851 firmwareFirmware per Cisco advisory; no specific ranges provided in source data
Cisco IP Phone 8861 firmwareFirmware per Cisco advisory; no specific ranges provided in source data
Cisco IP Phone 8865 firmwareFirmware per Cisco advisory; no specific ranges provided in source data
Estimated exposure
mass≈1,000,000+ deployed handsets across the affected 7800/8800 series models — Cisco's 7800 and 8800 series are among the most widely deployed enterprise IP phone lines with millions of units shipped, and the KEV listing plus a 100th-percentile EPSS score indicate broad real-world deployment; exact exposed-device…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

A vulnerability in the web server for Cisco IP Phones could allow an unauthenticated, remote attacker to execute code with root privileges or cause a reload of an affected IP phone, resulting in a denial of service (DoS) condition. The vulnerability is due to a lack of proper input validation of HTTP requests. An attacker could exploit this vulnerability by sending a crafted HTTP request to the web server of a targeted device. A successful exploit could allow the attacker to remotely execute code with root privileges or cause a reload of an affected IP phone, resulting in a DoS condition.

CISA Known Exploited Vulnerability
Affected
Cisco Cisco IP Phones
Required action
Apply updates per vendor instructions.
Due date
Ransomware use
Unknown
Vendors
cisco
Products
ip phone 8865 firmware, ip phone 8851 firmware, ip phone 7841 firmware, ip phone 7821 firmware, ip phone 8811 firmware, ip phone 8861 firmware, ip phone 8845 firmware, ip phone 7861 firmware, ip phone 8841 firmware, ip phone 7811 firmware, ip phone 8821 firmware, ip phone 8821-ex firmware
Weakness
CWE-20
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news