CVE-2020-3161
CRITICAL KEVCisco IP Phone Multiple Models Firmware - Unauthenticated RCE or DoS via HTTP
Title source: llmExploitation Summary
CVE-2020-3161 is actively exploited and listed in the CISA Known Exploited Vulnerabilities (KEV) catalog, added November 3, 2021. EIP tracks 2 public exploits from researchers including Jacob Baines, abood05972.
AI-analyzed exploit summary This exploit triggers a denial of service (DoS) in Cisco IP Phone versions before 11.7(1) by sending an excessively long activation code via a crafted HTTP request. The vulnerability is exploited through a buffer overflow in the device configuration endpoint.
Description
A vulnerability in the web server for Cisco IP Phones could allow an unauthenticated, remote attacker to execute code with root privileges or cause a reload of an affected IP phone, resulting in a denial of service (DoS) condition. The vulnerability is due to a lack of proper input validation of HTTP requests. An attacker could exploit this vulnerability by sending a crafted HTTP request to the web server of a targeted device. A successful exploit could allow the attacker to remotely execute code with root privileges or cause a reload of an affected IP phone, resulting in a DoS condition.
Exploits (2)
This exploit triggers a denial of service (DoS) in Cisco IP Phone versions before 11.7(1) by sending an excessively long activation code via a crafted HTTP request. The vulnerability is exploited through a buffer overflow in the device configuration endpoint.
This repository contains a functional Lua script that exploits CVE-2020-3161, a denial-of-service vulnerability in Cisco IP Phone 11.7. The exploit sends a maliciously crafted HTTP request with an excessively long 'params' value to trigger the DoS condition.
References (3)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H