Cisco IP Phones Web Server Remote Code Execution and Denial-of-Service Vulnerability
Cisco IP Phones용 웹 서버의 취약점으로 인해 인증되지 않은 원격 공격자가 root 권한으로 코드를 실행하거나 영향을 받는 IP phone을 다시 로드하여 서비스 거부(DoS) 상태를 유발할 수 있습니다. 이 취약점은 HTTP 요청에 대한 적절한 입력 검증이 부족하여 발생합니다. 공격자는 대상 장치의 웹 서버에 조작된 HTTP 요청을 전송하여 이 취약점을 악용할 수 있습니다. 악용에 성공하면 공격자가 원격에서 root 권한으로 코드를 실행하거나 영향을 받는 IP phone을 다시 로드하여 DoS 상태를 유발할 수 있습니다.
Cisco IP Phones용 웹 서버의 취약점으로 인해 인증되지 않은 원격 공격자가 root 권한으로 코드를 실행하거나 영향을 받는 IP phone을 다시 로드하여 서비스 거부(DoS) 상태를 유발할 수 있습니다. 이 취약점은 HTTP 요청에 대한 적절한 입력 검증이 부족하여 발생합니다. 공격자는 대상 장치의 웹 서버에 조작된 HTTP 요청을 전송하여 이 취약점을 악용할 수 있습니다. 악용에 성공하면 공격자가 원격에서 root 권한으로 코드를 실행하거나 영향을 받는 IP phone을 다시 로드하여 DoS 상태를 유발할 수 있습니다.
한국어 설명은 영문 원문을 기준으로 제공됩니다. 제품명·버전·보안 식별자는 아래 원문과 함께 확인할 수 있습니다.
영문 원문 보기
A vulnerability in the web server for Cisco IP Phones could allow an unauthenticated, remote attacker to execute code with root privileges or cause a reload of an affected IP phone, resulting in a denial of service (DoS) condition. The vulnerability is due to a lack of proper input validation of HTTP requests. An attacker could exploit this vulnerability by sending a crafted HTTP request to the web server of a targeted device. A successful exploit could allow the attacker to remotely execute code with root privileges or cause a reload of an affected IP phone, resulting in a DoS condition.
영향 제품·버전
제품 Cisco IP Phones
영향 버전 Cisco IP Phones 10.3(1)es14, 11.0(1), 11.0(5)sr1