ID

VAR-201205-0414


CVE

CVE-2012-1328


TITLE

Cisco Unified IP Phones 9900 Vulnerability gained in the firmware of series firmware

Trust: 0.8

sources: JVNDB: JVNDB-2012-002233

DESCRIPTION

Cisco Unified IP Phones 9900 series devices with firmware 9.1 and 9.2 do not properly handle downloads of configuration information to an RT phone, which allows local users to gain privileges via unspecified injected data, aka Bug ID CSCts32237. The problem is Bug ID CSCts32237 It is a problem.Local users may be able to gain privileges via unspecified insertion data

Trust: 1.98

sources: NVD: CVE-2012-1328 // JVNDB: JVNDB-2012-002233 // BID: 78228 // VULHUB: VHN-54609

AFFECTED PRODUCTS

vendor:ciscomodel:unified ip phonescope:eqversion:9.2

Trust: 2.7

vendor:ciscomodel:unified ip phonescope:eqversion:9.1

Trust: 2.7

vendor:ciscomodel:unified ip phonescope:eqversion:9900

Trust: 1.6

vendor:ciscomodel:unified ip phonescope:eqversion:9900 series

Trust: 0.8

vendor:ciscomodel:unified ip phonesscope:eqversion:9900

Trust: 0.3

sources: BID: 78228 // JVNDB: JVNDB-2012-002233 // CNNVD: CNNVD-201205-076 // NVD: CVE-2012-1328

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2012-1328
value: MEDIUM

Trust: 1.0

NVD: CVE-2012-1328
value: MEDIUM

Trust: 0.8

CNNVD: CNNVD-201205-076
value: MEDIUM

Trust: 0.6

VULHUB: VHN-54609
value: MEDIUM

Trust: 0.1

nvd@nist.gov: CVE-2012-1328
severity: MEDIUM
baseScore: 4.6
vectorString: AV:L/AC:L/AU:N/C:P/I:P/A:P
accessVector: LOCAL
accessComplexity: LOW
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: PARTIAL
availabilityImpact: PARTIAL
exploitabilityScore: 3.9
impactScore: 6.4
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.8

VULHUB: VHN-54609
severity: MEDIUM
baseScore: 4.6
vectorString: AV:L/AC:L/AU:N/C:P/I:P/A:P
accessVector: LOCAL
accessComplexity: LOW
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: PARTIAL
availabilityImpact: PARTIAL
exploitabilityScore: 3.9
impactScore: 6.4
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.1

sources: VULHUB: VHN-54609 // JVNDB: JVNDB-2012-002233 // CNNVD: CNNVD-201205-076 // NVD: CVE-2012-1328

PROBLEMTYPE DATA

problemtype:CWE-94

Trust: 1.9

sources: VULHUB: VHN-54609 // JVNDB: JVNDB-2012-002233 // NVD: CVE-2012-1328

THREAT TYPE

local

Trust: 0.9

sources: BID: 78228 // CNNVD: CNNVD-201205-076

TYPE

code injection

Trust: 0.6

sources: CNNVD: CNNVD-201205-076

CONFIGURATIONS

sources: JVNDB: JVNDB-2012-002233

PATCH

title:Cisco Unified IP Phones 8961, 9951, and 9971(SIP) Release Notes for Firmware Release 9.2(3)url:http://www.cisco.com/en/US/docs/voice_ip_comm/cuipph/9971_9951_8961/firmware/9_2_3/release_notes/9900_8900_923.html

Trust: 0.8

sources: JVNDB: JVNDB-2012-002233

EXTERNAL IDS

db:NVDid:CVE-2012-1328

Trust: 2.8

db:JVNDBid:JVNDB-2012-002233

Trust: 0.8

db:CNNVDid:CNNVD-201205-076

Trust: 0.7

db:BIDid:78228

Trust: 0.4

db:SEEBUGid:SSVID-91775

Trust: 0.1

db:VULHUBid:VHN-54609

Trust: 0.1

sources: VULHUB: VHN-54609 // BID: 78228 // JVNDB: JVNDB-2012-002233 // CNNVD: CNNVD-201205-076 // NVD: CVE-2012-1328

REFERENCES

url:http://www.cisco.com/en/us/docs/voice_ip_comm/cuipph/9971_9951_8961/firmware/9_2_3/release_notes/9900_8900_923.html

Trust: 2.0

url:https://exchange.xforce.ibmcloud.com/vulnerabilities/75412

Trust: 1.1

url:http://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2012-1328

Trust: 0.8

url:http://web.nvd.nist.gov/view/vuln/detail?vulnid=cve-2012-1328

Trust: 0.8

sources: VULHUB: VHN-54609 // BID: 78228 // JVNDB: JVNDB-2012-002233 // CNNVD: CNNVD-201205-076 // NVD: CVE-2012-1328

CREDITS

Unknown

Trust: 0.3

sources: BID: 78228

SOURCES

db:VULHUBid:VHN-54609
db:BIDid:78228
db:JVNDBid:JVNDB-2012-002233
db:CNNVDid:CNNVD-201205-076
db:NVDid:CVE-2012-1328

LAST UPDATE DATE

2024-11-23T22:35:29.177000+00:00


SOURCES UPDATE DATE

db:VULHUBid:VHN-54609date:2017-12-07T00:00:00
db:BIDid:78228date:2012-05-03T00:00:00
db:JVNDBid:JVNDB-2012-002233date:2012-05-08T00:00:00
db:CNNVDid:CNNVD-201205-076date:2012-05-04T00:00:00
db:NVDid:CVE-2012-1328date:2024-11-21T01:36:49.533

SOURCES RELEASE DATE

db:VULHUBid:VHN-54609date:2012-05-03T00:00:00
db:BIDid:78228date:2012-05-03T00:00:00
db:JVNDBid:JVNDB-2012-002233date:2012-05-08T00:00:00
db:CNNVDid:CNNVD-201205-076date:2012-05-04T00:00:00
db:NVDid:CVE-2012-1328date:2012-05-03T23:55:01.403