CVE-2020-3161
악용 확인 Cisco IP Phones Web Server Remote Code Execution and Denial-of-Service Vulnerability
악용 여부
악용 확인
심각도 (발행처 발표값)
심각9.8
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
악용 확률 (EPSS)
83.9%
한국어 공식 권고
CISA 원문
Cisco IP Phones contain an improper input validation vulnerability for HTTP requests. Exploitation could allow an attacker to execute code remotely with root privileges or cause a denial-of-service (DoS) condition.— CISA KEV · shortDescription 원문
Apply updates per vendor instructions.— CISA KEV · requiredAction 원문
취약점 설명 (NVD 원문)
A vulnerability in the web server for Cisco IP Phones could allow an unauthenticated, remote attacker to execute code with root privileges or cause a reload of an affected IP phone, resulting in a denial of service (DoS) condition. The vulnerability is due to a lack of proper input validation of HTTP requests. An attacker could exploit this vulnerability by sending a crafted HTTP request to the web server of a targeted device. A successful exploit could allow the attacker to remotely execute code with root privileges or cause a reload of an affected IP phone, resulting in a DoS condition.
CWE-20 CWE-20
악용 확률 변화
| 기준일 | 확률 | 백분위 |
|---|---|---|
| 2026-09-05 | 83.86% | 99.7% |
| 2026-09-04 | 83.86% | 99.7% |