vendor:
Cisco IP Phone
by:
Jacob Baines
9.8
CVSS
CRITICAL
Denial of Service
400
CWE
Product Name: Cisco IP Phone
Affected Version From: Before 11.7(1)
Affected Version To: 11.7(1)
Patch Exists: YES
Related CWE: CVE-2020-3161
CPE: a:cisco:ip_phone:11.7
Platforms Tested: Cisco Wireless IP Phone 8821
2020
Cisco IP Phone 11.7 – Denial of Service
The Cisco IP Phone 11.7 is vulnerable to a Denial of Service (DoS) attack. By sending a specially crafted request to the device, an attacker can cause the phone to become unresponsive and stop functioning. This can disrupt communication and potentially impact business operations. The vulnerability has been assigned CVE-2020-3161.
Mitigation:
Cisco has released a software update that addresses this vulnerability. Users are advised to upgrade to Cisco IP Phone firmware version 11.7(1) or later. Additionally, network administrators should implement proper access controls and monitoring to detect and prevent unauthorized access to the phone.