cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
820
Views
25
Helpful
3
Replies

CSCvs78272 - Cisco IP Phones Web Server Remote Code Execution and Denial of Service Vulnerability

Patrick.Brandt
Level 1
Level 1

Hi there!

 

From the advisory and bug id I wasnt able to tell our IT Security department if the release 11.0(5)SR2 is a fixed or affected release.

Does anyone can tell this for sure?

 

Thanks in advance!

3 Replies 3

Wes Sisk
Cisco Employee
Cisco Employee

The fixed releases indicates 11.0(05)SR03. 

Hey, thanks for the reply! I saw that, but it also shows only 11.0(5)SR1 as affected not SR2.

 

Yes, in this product line fixes are cumulative unless otherwise stated. if sr1 is affected then it is assumed sr2 is affected until it is specifically listed as fixed in sr3.

 

sr2 list of fixed bugs, note CSCvs78272 is not cited as resolved

https://www.cisco.com/c/en/us/td/docs/voice_ip_comm/cuipph/8821/firmware/11-0-5sr2/w881_b_wireless-8821-rns-110005sr2.html#reference_E6AC67E2478029DC70A7B897451A4486