Cisco Unified IP Phones 7900 devices (aka TNP phones) with software before 9.2.1 do not properly verify signatures for software images, which allows local users to gain privileges via a crafted image, aka Bug ID CSCtn65962.
Metrics
No CVSS v4.0
No CVSS v3.1
No CVSS v3.0
Access Vector Local
Access Complexity Medium
Authentication Single
Confidentiality Impact Partial
Integrity Impact None
Availability Impact None
This CVE is not in the KEV list.
The EPSS score is 0.00105.
Key SSVC decision points have not yet been added.
Affected Vendors & Products
| Vendors | Products |
|---|---|
|
Cisco
Subscribe
|
Skinny Client Control Protocol Software
Subscribe
Unified Ip Phone 7906
Subscribe
Unified Ip Phone 7911g
Subscribe
Unified Ip Phone 7931g
Subscribe
Unified Ip Phone 7941g
Subscribe
Unified Ip Phone 7941g-ge
Subscribe
Unified Ip Phone 7942g
Subscribe
Unified Ip Phone 7945g
Subscribe
Unified Ip Phone 7961g
Subscribe
Unified Ip Phone 7961g-ge
Subscribe
Unified Ip Phone 7962g
Subscribe
Unified Ip Phone 7965g
Subscribe
Unified Ip Phone 7970g
Subscribe
Unified Ip Phone 7971g-ge
Subscribe
Unified Ip Phone 7975g
Subscribe
|
Configuration 1 [-]
| AND |
|
No data.
No data.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2011-1637 | Cisco Unified IP Phones 7900 devices (aka TNP phones) with software before 9.2.1 do not properly verify signatures for software images, which allows local users to gain privileges via a crafted image, aka Bug ID CSCtn65962. |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
No history.
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: cisco
Published:
Updated: 2024-08-06T22:37:24.683Z
Reserved: 2011-04-05T00:00:00
Link: CVE-2011-1637
No data.
Status : Deferred
Published: 2011-06-02T20:55:03.480
Modified: 2025-04-11T00:51:21.963
Link: CVE-2011-1637
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD