#VU13859 OS command injection in Cisco Systems, Inc products - CVE-2018-0341
Published: July 11, 2018 / Updated: July 13, 2018
Cisco 8800 Series IP Phones
Cisco 7800 Series IP Phones
Cisco 6800 Series IP Phones
Cisco Systems, Inc
Description
The vulnerability allows a remote authenticated attacker to execute arbitrary OS commands on the target system.
The vulnerability exists in the web-based UI due to insufficient input validation. A remote attacker can include arbitrary shell commands in a specific user input field and execute arbitrary shell commands with elevated privileges.