ZeroHour
Help Net Securitypublished ()ingested @zeljkazorz

Using Cisco IP phones? Fix these critical vulnerabilities

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2016-1421
A vulnerability in the web application for Cisco IP Phones could allow an unauthenticated, remote attacker to execute code with root privileges or cause a reloa

A vulnerability in the web application for Cisco IP Phones could allow an unauthenticated, remote attacker to execute code with root privileges or cause a reload of an affected IP phone, resulting in a denial of service (DoS) condition. The vulnerability exists because the affected software fails to check the bounds of input data. An attacker could exploit this vulnerability by sending a crafted HTTP request to the web server of a targeted device. A successful exploit could allow the attacker to remotely execute code with root privileges or cause a reload of an affected IP phone, resulting in a DoS condition.

NVD description · AI analysis pending
7.54%
  • cisco ip phone 8800 series firmware
CVE-2020-3161
Unauthenticated RCE/DoS in Cisco IP Phone Web Server

CVE-2020-3161 is a critical (CVSS 9.8) input-validation flaw (CWE-20) in the web server of multiple Cisco IP Phone 7800 and 8800 series models, including the 7811, 7821, 7841, 7861, 8811, 8841, 8845, 8851, 8861, 8865, 8821 and 8821-EX. An unauthenticated remote attacker can trigger it simply by sending a crafted HTTP request to the web server of a targeted phone, with no credentials or user interaction required. A successful exploit allows the attacker to execute code with root privileges on the device or force a reload, causing a denial-of-service condition. Any organization running the listed Cisco IP phone models where the phone's web server is reachable over the network is affected. The flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2021-11-03, carries a very high EPSS score of 83.9% (100th percentile), and a public denial-of-service proof of concept targeting the 11.7 firmware is available.

Do: Apply updated firmware for all listed 7800/8800 series models per Cisco's instructions, as required by the CISA KEV catalog. Until phones are patched, restrict or disable the phone web server and limit HTTP access to trusted management networks, and inventory your environment for these models to confirm none are exposed to untrusted users.

9.884% KEV PoC
  • Cisco IP Phone 7811 firmware Firmware per Cisco advisory; no specific ranges provided in source data
  • Cisco IP Phone 7821 firmware Firmware per Cisco advisory; no specific ranges provided in source data
  • Cisco IP Phone 7841 firmware Firmware per Cisco advisory; no specific ranges provided in source data
  • +9 more
mass≈1,000,000+ deployed handsets across the affected 7800/8800 series models
Full article487 words · extracted from helpnetsecurity.com · click to collapse

Cisco has released another batch of fixes for a number of its products. Among the vulnerabilities fixed are critical flaws affecting a variety of Cisco IP phones and Cisco UCS Director and Cisco UCS Director Express for Big Data, its unified infrastructure management solutions for data center operations.

Cisco IP phones vulnerabilities

The critical vulnerabilities

Jacob Baines, a research engineer with Tenable, unearthed two critical flaws affecting the Cisco Wireless IP Phone 8821. Cisco then tested other IP phones and found several series that were affected, as well.

CVE-2020-3161 affects the web server and CVE-2016-1421 the web application for Cisco IP Phones. Both may allow an unauthenticated remote attacker to trigger a stack-based buffer overflow by sending a crafted HTTP request, which could ultimately lead to a DoS condition or may allow the attacker to execute code with root privileges.

If you’re wondering why the CVE of the latter vulnerability indicates that it was reported in 2016, it’s because it (partly) was.

“During Tenable’s original analysis, they noted the similarity of this vulnerability to [a previously discovered bug]. However, Cisco’s advisory described the vulnerability as requiring authentication, DoS only, and the Wireless IP Phone 8821 wasn’t listed on the affected list. After disclosing to Cisco, they informed Tenable that the described bug was CVE-2016-1421 and subsequently updated their disclosure,” Tenable explained.

Admins are advised to check whether the IP phones in use in their enterprise and upgrade the firmware if they are. There are no workarounds for the flaws, but exploitation risk can be mitigated by disabling web access. Web access is disabled by default on Cisco IP phones, but some enterprises might have enabled it.

Baines has published Denial of Service PoCs for both flaws on Tenable’s GitHub repository.

Cisco has also provided fixes for nine authentication bypass vulnerabilities in the REST API of Cisco UCS Director and Cisco UCS Director Express for Big Data.

Only one of these is deemed to be critical. Exploiting one or several of these can allow a remote attacker to bypass authentication or conduct directory traversal attacks on an affected device.

Admins are advised to upgrade to UCS Director Release 6.7.4.0 and UCS Director Express for Big Data Release 3.7.4.0 to plug the security holes.

The flaws were discovered by infosec specialist Steven Seeley of Source Incite, who promised to provide more details about the vulnerabilities soon.

The high-risk vulnerabilities

Two DoS flaws have been plugged in Cisco Wireless LAN Controllers, one in Cisco Aironet Series Access Points, and one in the Cisco IoT Field Network Director.

A code execution flaw in Cisco Webex Network Recording Player and Cisco Webex Player requires victim action to be exploited, and so does a CSRF flaw in Cisco Mobility Express Software.

Finally, a path traversal vulnerability in Cisco Unified Communications Manager (UCM) and Cisco Unified Communications Manager Session Management Edition (SME) could allow an unauthenticated, remote attacker to read arbitrary files in the system.

Text extracted automatically; images, tables and formatting may be missing. Original: https://www.helpnetsecurity.com/2020/04/16/cisco-ip-phones-vulnerabilities/