CVE-2013-6685
Published Nov 13, 2013
Last updated 11 years ago
Overview
- Description
- The firmware on Cisco Unified IP phones 8961, 9951, and 9971 uses weak permissions for memory block devices, which allows local users to gain privileges by mounting a device with a setuid file in its filesystem, aka Bug ID CSCui04382.
- Source
- ykramarz@cisco.com
- NVD status
- Analyzed
Social media
- Hype score
- Not currently trending
Risk scores
CVSS 2.0
- Type
- Primary
- Base score
- 6.6
- Impact score
- 10
- Exploitability score
- 2.7
- Vector string
- AV:L/AC:M/Au:S/C:C/I:C/A:C
Weaknesses
- nvd@nist.gov
- CWE-264
Configurations
[ { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:o:cisco:unified_ip_phone_firmware:-:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "78000E12-B4AA-4678-B1BC-B5AAD12E2C5A" } ], "operator": "OR" }, { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:h:cisco:unified_ip_phone_8961:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "53681FDE-9140-44E7-872C-D7D45BA99899" }, { "criteria": "cpe:2.3:h:cisco:unified_ip_phone_9951:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "5577F66E-FCAD-4FE4-9E12-A824FD5B37E3" }, { "criteria": "cpe:2.3:h:cisco:unified_ip_phone_9971:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "0BE3EAE9-ED3B-4E53-ABCE-65A65BD2E7EA" } ], "operator": "OR" } ], "operator": "AND" } ]