OS command injection in Cisco Systems, Inc products - CVE-2018-0341

 

OS command injection in Cisco Systems, Inc products - CVE-2018-0341

Published: July 11, 2018 / Updated: July 13, 2018


Vulnerability identifier: #VU13859
CSH Severity: High
CVSS v4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2018-0341
CWE-ID: CWE-78
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote authenticated attacker to execute arbitrary OS commands on the target system.

The vulnerability exists in the web-based UI due to insufficient input validation. A remote attacker can include arbitrary shell commands in a specific user input field and execute arbitrary shell commands with elevated privileges.


Affected software

Cisco 8800 Series IP Phones
Cisco 7800 Series IP Phones
Cisco 6800 Series IP Phones

How to mitigate CVE-2018-0341

Install update from vendor's website.


External References

Related Security Bulletins