Risk | Low |
Patch available | YES |
Number of vulnerabilities | 1 |
CVE-ID | CVE-2021-33478 |
CWE-ID | CWE-119 |
Exploitation vector | Local |
Public exploit | N/A |
Vulnerable software |
Cisco IP Phone 8800 Series with Multiplatform Firmware Hardware solutions / Office equipment, IP-phones, print servers Cisco IP Phone 8811 with Multiplatform Firmware Hardware solutions / Office equipment, IP-phones, print servers Cisco IP Phone 8841 with Multiplatform Firmware Hardware solutions / Office equipment, IP-phones, print servers Cisco IP Phone 8851 with Multiplatform Firmware Hardware solutions / Office equipment, IP-phones, print servers Cisco IP Phone 8861 with Multiplatform Firmware Hardware solutions / Office equipment, IP-phones, print servers Cisco IP Phone 8845 with Multiplatform Firmware Hardware solutions / Office equipment, IP-phones, print servers Cisco IP Phone 8865 with Multiplatform Firmware Hardware solutions / Office equipment, IP-phones, print servers Cisco IP Phone 8845 Hardware solutions / Office equipment, IP-phones, print servers Cisco IP Phone 8800 Series Hardware solutions / Office equipment, IP-phones, print servers Cisco IP Phone 8811 Hardware solutions / Office equipment, IP-phones, print servers Cisco IP Phone 8841 Hardware solutions / Office equipment, IP-phones, print servers Cisco IP Phone 8851 Hardware solutions / Office equipment, IP-phones, print servers Cisco Wireless IP Phone 8821 Hardware solutions / Office equipment, IP-phones, print servers Cisco IP Phone 8865 Hardware solutions / Routers & switches, VoIP, GSM, etc Cisco IP Phone 8861 Hardware solutions / Routers & switches, VoIP, GSM, etc |
Vendor | Cisco Systems, Inc |
Security Bulletin
This security bulletin contains one low risk vulnerability.
EUVDB-ID: #VU54621
Risk: Low
CVSSv4.0: 4 [CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Clear]
CVE-ID: CVE-2021-33478
CWE-ID:
CWE-119 - Memory corruption
Exploit availability: No
DescriptionThe vulnerability allows a local attacker to execute arbitrary code on the target system.
The vulnerability exists due to a boundary error in the TrustZone implementation. An attacker with physical access can dismount the backplate of the device, trigger a specific series of impulses on the chipset and execute arbitrary code on the target system.
MitigationInstall updates from vendor's website.
Vulnerable software versionsCisco IP Phone 8800 Series with Multiplatform Firmware: before 11.3.4
Cisco IP Phone 8811 with Multiplatform Firmware: before 11.3.4
Cisco IP Phone 8841 with Multiplatform Firmware: before 11.3.4
Cisco IP Phone 8851 with Multiplatform Firmware: before 11.3.4
Cisco IP Phone 8861 with Multiplatform Firmware: before 11.3.4
Cisco IP Phone 8845 with Multiplatform Firmware: before 11.3.4
Cisco IP Phone 8865 with Multiplatform Firmware: before 11.3.4
Cisco IP Phone 8845: before 14.0.1
Cisco IP Phone 8865: before 14.0.1
Cisco IP Phone 8800 Series: before 14.0.1
Cisco IP Phone 8811: before 14.0.1
Cisco IP Phone 8841: before 14.0.1
Cisco IP Phone 8851: before 14.0.1
Cisco IP Phone 8861: before 14.0.1
Cisco Wireless IP Phone 8821: before 11.0.6 SR1
CPE2.3Q & A
Can this vulnerability be exploited remotely?
No. The attacker should have physical access to the system in order to successfully exploit this vulnerability.
How the attacker can exploit this vulnerability?
The attacker would have to send a specially crafted request to the affected device in order to exploit this vulnerability.
Is there known malware, which exploits this vulnerability?
No. We are not aware of malware exploiting this vulnerability.