EXPOSURES › CVE-2020-3161
CVE-2020-3161
HIGH ⌖ ON CISA KEV · EXPLOITEDCisco IP phones had an unpatched remote code execution vulnerability exploited in the wild, allowing attackers to gain root access.
Cisco IP phones contained an improper input validation flaw in their web server that allowed remote code execution with root privileges. This unpatched vulnerability was actively exploited in the wild, posing a severe risk to DIB organizations relying on Cisco hardware for network access and voice communications. Organizations must ensure all Cisco IP phones are patched to prevent attackers from executing arbitrary code and compromising network infrastructure.
Shame score — The vulnerability was unpatched and actively exploited in the wild, demonstrating a failure to address known security flaws and leaving critical network hardware vulnerable to remote code execution.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Cisco IP Phones contain an improper input validation vulnerability for HTTP requests. Exploitation could allow an attacker to execute code remotely with root privileges or cause a denial-of-service (DoS) condition.
| PRODUCT | STATUS |
|---|---|
| AppDynamics GovAPM AppDynamics (a Cisco company) |
Authorized |
| Cisco Cloudlock for Government Cisco Systems Inc. |
Authorized |
| Cisco Meraki for Government Cisco Systems Inc. |
In Process |
| Cisco SD-WAN for Government Cisco Systems Inc. |
In Process |
| Cisco Umbrella for Government Cisco Systems Inc. |
In Process |
| Cisco Unified Communications Manager Cloud for Government (Cisco UCM Cloud for Government) Cisco Systems Inc. |
Authorized |
| Duo Federal Duo Security (A Cisco Company) |
Authorized |
| WebEx Contact Center Enterprise for Government (WxCCE-G) Cisco Systems Inc. |
In Process |
| Webex for Government Cisco Systems Inc. |
Authorized |