Improper Filesystem Permissions in Cisco 8800 Series IP Phones
CVE-2016-1435

7HIGH

Key Information:

Vendor
Cisco
Vendor
CVE Published:
23 June 2016

Summary

The Cisco 8800 Series IP Phones running software version 11.0(1) contain a vulnerability that allows local users to write to arbitrary files due to inadequate enforcement of filesystem permissions. This flaw could be exploited by an attacker who has shell access, leading to potential unauthorized access and modification of critical system files. Organizations using these devices should ensure appropriate security measures are in place to mitigate the risks associated with this vulnerability.

References

CVSS V3.1

Score:
7
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.