CVE-2020-3161
Cisco IP Phones Web Server Remote Code Execution and Denial-of-Service Vulnerability
⚠ KEVEPSS 83.7%
Description
Cisco IP Phones contain an improper input validation vulnerability for HTTP requests. Exploitation could allow an attacker to execute code remotely with root privileges or cause a denial-of-service (DoS) condition.
How to fix CVE-2020-3161
No package mapping is available — consult the references below for vendor-specific guidance.
Is CVE-2020-3161 being exploited?
Yes — CVE-2020-3161 is on the CISA Known Exploited Vulnerabilities (KEV) catalog. Patch immediately.
Affected packages (0)
No package mapping in OSV.