Cisco Unified IP Phones 7900 Series Unsigned Code Installation Vulnerability

Cisco-SA-20110601-CVE-2011-1637 · Medium · Published · Updated

Cisco Unified IP Phones 7900 Series devices contain a vulnerability that could allow an authenticated, local attacker to load a software image without verification. The vulnerability is due to insecure security checks on software images.  An authenticated, local attacker could exploit this vulnerability to bypass signature verification and load a software image on a targeted device. Cisco has confirmed this vulnerability in a security advisory and has released updated software. A potential attacker would need to authenticate to an affected device, which would likely require an attacker to gain access to an internal, trusted network.  These factors could mitigate a possible attack. Cisco indicates through the CVSS score that functional exploit code exists; however, the code is not known to be publicly available.

Workarounds

Administrators are advised to apply the appropriate updates.

Administrators are advised to allow only trusted users to access local systems.

Administrators are advised to monitor affected systems.

CVEsCVE-2011-1637
Cisco Bug IDsNA
CVSS ScoreBase 1.5
Base 1.5 AV:L/AC:M/Au:S/C:P/I:N/A:N/E:F/RL:OF/RC:C/CDP:N/TD:N/CR:ND/IR:ND/AR:ND

Public Affected Products