Cisco Unified IP Phones 7900 devices (aka TNP phones) with software before 9.2.1 do not properly verify signatures for software images, which allows local users to gain privileges via a crafted image, aka Bug ID CSCtn65962.
Weaknesses in this category are related to the management of permissions, privileges, and other security features that are used to perform access control.
Link | Tags |
---|---|
http://www.securitytracker.com/id?1025588 | vdb entry |
http://secunia.com/advisories/44814/ | third party advisory |
http://www.securityfocus.com/bid/48075 | vdb entry |
http://osvdb.org/72719 | vdb entry |
http://www.cisco.com/en/US/products/products_security_advisory09186a0080b80111.shtml | vendor advisory |
https://exchange.xforce.ibmcloud.com/vulnerabilities/67743 | vdb entry |