cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
513
Views
0
Helpful
3
Replies

Ejecución de código arbitrario en la familia de teléfonos Cisco Unified IP 7900

Hola quisiera saber si esta vulnerabilidad

Ejecución de código arbitrario en la familia de teléfonos Cisco Unified IP 7900

esta reconocida oficialmente por Cisco y si en realidad afecta a toda la serie 7900, de la cual se habla en el siguiente enlance :

http://unaaldia.hispasec.com/2013/01/ejecucion-de-codigo-arbitrario-en-la.html

Gracias.

1 Accepted Solution

Accepted Solutions

Harmit Singh
Cisco Employee
Cisco Employee
3 Replies 3

Harmit Singh
Cisco Employee
Cisco Employee

Hi Jorge,

Here is the defect ID to track this vulnerability:

http://tools.cisco.com/Support/BugToolKit/search/getBugDetails.do?method=fetchBugDetails&bugId=CSCuc83860

HTH.

Regards,

Harmit.

TY for your answer, another question how can i validate this on my phones:

Conditions:


Cisco Unified IP Phones within the 7900 Series running a version of Cisco IP Phone software up to and including 9.3.1-ES10 are affected

Hi Jorge,

If you have any of the following phone models, irrespective of the firmware you are running at this time, they are vulnerable:

The following Cisco Unified IP Phone devices are affected:

Cisco Unified IP Phone 7975G

Cisco Unified IP Phone 7971G-GE

Cisco Unified IP Phone 7970G

Cisco Unified IP Phone 7965G

Cisco Unified IP Phone 7962G

Cisco Unified IP Phone 7961G

Cisco Unified IP Phone 7961G-GE

Cisco Unified IP Phone 7945G

Cisco Unified IP Phone 7942G

Cisco Unified IP Phone 7941G

Cisco Unified IP Phone 7941G-GE

Cisco Unified IP Phone 7931G

Cisco Unified IP Phone 7911G

Cisco Unified IP Phone 7906


The following models have reached end-of-life (EOL) status (for hardware only):

Cisco Unified IP Phone 7971G-GE

Cisco Unified IP Phone 7970G

Cisco Unified IP Phone 7961G

Cisco Unified IP Phone 7961G-GE

Cisco Unified IP Phone 7941G

Cisco Unified IP Phone 7941G-GE

Cisco Unified IP Phone 7906


Refer to the following link to determine what product upgrade and substitution options are available:

http://www.cisco.com/en/US/products/hw/phones/ps379/prod_eol_notices_list.html

So in other words, the latest firmware 9.3.1 with the latest ES-10 is vulnerable. The fix is yet to be released. Please keep a check on the defect to see when the fix is released.

HTH.

Regards,

Harmit.