CVE-2018-0461 (CNNVD-201901-295)
中文标题:
Cisco IP Phone 8800 Series Software 代码注入漏洞
英文标题:
Cisco IP Phone 8800 Series Arbitrary Script Injection Vulnerability
漏洞描述
中文描述:
Cisco IP Phone 8800 Series是美国思科(Cisco)公司的一款提供视频和VoIP通信功能的电话产品。Cisco IP Phone 8800 Series Software是运行在其中的一套软件。 Cisco IP Phone 8800 Series Software中存在代码注入漏洞,该漏洞源于程序没有充分验证用户提交的数据。远程攻击者可借助特制的链接利用该漏洞在用户界面的上下文中执行任意脚本代码或访问基于系统的敏感信息。
英文描述:
A vulnerability in the Cisco IP Phone 8800 Series Software could allow an unauthenticated, remote attacker to conduct an arbitrary script injection attack on an affected device. The vulnerability exists because the software running on an affected device insufficiently validates user-supplied data. An attacker could exploit this vulnerability by persuading a user to click a malicious link provided to the user or through the interface of an affected device. A successful exploit could allow an attacker to execute arbitrary script code in the context of the user interface or access sensitive system-based information, which under normal circumstances should be prohibited.
CWE类型:
标签:
受影响产品
| 厂商 | 产品 | 版本 | 版本范围 | 平台 | CPE |
|---|---|---|---|---|---|
| Cisco | Cisco IP Phone 8800 Series Software | n/a | - | - |
cpe:2.3:a:cisco:cisco_ip_phone_8800_series_software:n_a:*:*:*:*:*:*:*
|
| cisco | ip_phone_8800_series_firmware | 12.5\(1\) | - | - |
cpe:2.3:o:cisco:ip_phone_8800_series_firmware:12.5\(1\):*:*:*:*:*:*:*
|
解决方案
中文解决方案:
英文解决方案:
临时解决方案:
CVSS评分详情
3.0 (cna)
MEDIUMCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
时间信息
利用信息
数据源详情
| 数据源 | 记录ID | 版本 | 提取时间 |
|---|---|---|---|
| CVE | cve_CVE-2018-0461 |
2025-11-11 15:19:35 | 2025-11-11 07:34:57 |
| NVD | nvd_CVE-2018-0461 |
2025-11-11 14:56:02 | 2025-11-11 07:43:33 |
| CNNVD | cnnvd_CNNVD-201901-295 |
2025-11-11 15:10:08 | 2025-11-11 07:54:17 |
版本与语言
安全公告
变更历史
查看详细变更
- vulnerability_type: 未提取 -> 代码注入
- cnnvd_id: 未提取 -> CNNVD-201901-295
- data_sources: ['cve', 'nvd'] -> ['cnnvd', 'cve', 'nvd']
查看详细变更
- affected_products_count: 1 -> 2
- data_sources: ['cve'] -> ['cve', 'nvd']