A vulnerability in the debug shell of Cisco IP Phone software could allow an authenticated, local attacker to read any file on the device file system. This vulnerability is due to insufficient input validation. An attacker could exploit this vulnerability by providing crafted input to a debug shell command. A successful exploit could allow the attacker to read any file on the device file system.
References
Configurations
Configuration 1 (hide)
AND |
|
Configuration 2 (hide)
AND |
|
Configuration 3 (hide)
AND |
|
Configuration 4 (hide)
AND |
|
Configuration 5 (hide)
AND |
|
Configuration 6 (hide)
AND |
|
Configuration 7 (hide)
AND |
|
Configuration 8 (hide)
AND |
|
Configuration 9 (hide)
AND |
|
Configuration 10 (hide)
AND |
|
Configuration 11 (hide)
AND |
|
Configuration 12 (hide)
AND |
|
Configuration 13 (hide)
AND |
|
Configuration 14 (hide)
AND |
|
Configuration 15 (hide)
AND |
|
Configuration 16 (hide)
AND |
|
History
21 Nov 2024, 06:11
Type | Values Removed | Values Added |
---|---|---|
References | () https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ipphone-arbfileread-NPdtE2Ow - Vendor Advisory |
14 Oct 2021, 21:12
Type | Values Removed | Values Added |
---|---|---|
CPE | cpe:2.3:o:cisco:ip_phone_7811_firmware:*:*:*:*:*:*:*:* cpe:2.3:h:cisco:ip_phones_8832:-:*:*:*:*:*:*:* cpe:2.3:o:cisco:ip_phone_8845_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:cisco:ip_phone_8841_firmware:*:*:*:*:*:*:*:* cpe:2.3:h:cisco:ip_phone_8811:-:*:*:*:*:*:*:* cpe:2.3:h:cisco:ip_phone_7832:-:*:*:*:*:*:*:* cpe:2.3:o:cisco:ip_phone_7821_firmware:*:*:*:*:*:*:*:* cpe:2.3:h:cisco:ip_phone_8831:-:*:*:*:*:*:*:* cpe:2.3:o:cisco:ip_phone_8851_firmware:*:*:*:*:*:*:*:* cpe:2.3:h:cisco:ip_phone_8851:-:*:*:*:*:*:*:* cpe:2.3:h:cisco:ip_conference_phone_7832:-:*:*:*:*:*:*:* cpe:2.3:h:cisco:ip_conference_phone_8832:-:*:*:*:*:*:*:* cpe:2.3:h:cisco:wireless_ip_phone_8821:-:*:*:*:*:*:*:* cpe:2.3:o:cisco:ip_phone_8831_firmware:*:*:*:*:*:*:*:* cpe:2.3:h:cisco:ip_phone_7821:-:*:*:*:*:*:*:* cpe:2.3:o:cisco:ip_conference_phone_7832_firmware:*:*:*:*:*:*:*:* cpe:2.3:h:cisco:ip_phone_7841:-:*:*:*:*:*:*:* cpe:2.3:o:cisco:wireless_ip_phone_8821_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:cisco:ip_phone_8861_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:cisco:ip_phone_7841_firmware:*:*:*:*:*:*:*:* cpe:2.3:h:cisco:ip_phone_7811:-:*:*:*:*:*:*:* cpe:2.3:o:cisco:ip_phone_7832_firmware:*:*:*:*:*:*:*:* cpe:2.3:h:cisco:ip_phone_8845:-:*:*:*:*:*:*:* cpe:2.3:h:cisco:ip_phone_8861:-:*:*:*:*:*:*:* cpe:2.3:o:cisco:ip_phone_8811_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:cisco:ip_conference_phone_8832_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:cisco:ip_phone_8865_firmware:*:*:*:*:*:*:*:* cpe:2.3:h:cisco:ip_phone_8841:-:*:*:*:*:*:*:* cpe:2.3:h:cisco:ip_phone_8865:-:*:*:*:*:*:*:* cpe:2.3:o:cisco:ip_phones_8832_firmware:*:*:*:*:*:*:*:* cpe:2.3:h:cisco:ip_phone_7861:-:*:*:*:*:*:*:* cpe:2.3:o:cisco:ip_phone_7861_firmware:*:*:*:*:*:*:*:* |
|
CWE | CWE-22 | |
CVSS |
v2 : v3 : |
v2 : 2.1
v3 : 5.5 |
References | (CISCO) https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ipphone-arbfileread-NPdtE2Ow - Vendor Advisory |
06 Oct 2021, 20:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2021-10-06 20:15
Updated : 2024-11-21 06:11
NVD link : CVE-2021-34711
Mitre link : CVE-2021-34711
CVE.ORG link : CVE-2021-34711
JSON object : View
Products Affected
cisco
- ip_phones_8832
- ip_phone_8811_firmware
- wireless_ip_phone_8821_firmware
- ip_phone_8831
- ip_phone_7821
- ip_phones_8832_firmware
- ip_phone_8845
- wireless_ip_phone_8821
- ip_conference_phone_8832_firmware
- ip_conference_phone_8832
- ip_phone_8831_firmware
- ip_phone_7861_firmware
- ip_phone_8851
- ip_phone_7821_firmware
- ip_phone_8845_firmware
- ip_phone_7811
- ip_phone_7861
- ip_phone_8851_firmware
- ip_phone_7832
- ip_phone_8841_firmware
- ip_conference_phone_7832
- ip_phone_7841
- ip_phone_7832_firmware
- ip_phone_8865_firmware
- ip_phone_8811
- ip_phone_8865
- ip_phone_8841
- ip_phone_7841_firmware
- ip_phone_7811_firmware
- ip_phone_8861
- ip_conference_phone_7832_firmware
- ip_phone_8861_firmware