The firmware on Cisco Unified IP phones 8961, 9951, and 9971 uses weak permissions for memory block devices, which allows local users to gain privileges by mounting a device with a setuid file in its filesystem, aka Bug ID CSCui04382.
2013-11-13T15:55:04.550
2025-04-11T00:51:21.963
Deferred
CVSSv2: 6.6 (MEDIUM)
AV:L/AC:M/Au:S/C:C/I:C/A:C
2.7
10.0
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Operating System | cisco | unified_ip_phone_firmware | - | Yes |
Hardware | cisco | unified_ip_phone_8961 | * | Yes |
Hardware | cisco | unified_ip_phone_9951 | * | Yes |
Hardware | cisco | unified_ip_phone_9971 | * | Yes |