CVE-2011-1637

Severity CVSS v4.0:
Pending analysis
Type:
CWE-264 Permissions, Privileges, and Access Control
Publication date:
02/06/2011
Last modified:
11/04/2025

Description

Cisco Unified IP Phones 7900 devices (aka TNP phones) with software before 9.2.1 do not properly verify signatures for software images, which allows local users to gain privileges via a crafted image, aka Bug ID CSCtn65962.

Vulnerable products and versions

CPE From Up to
cpe:2.3:h:cisco:unified_ip_phone_7906:*:*:*:*:*:*:*:*
cpe:2.3:h:cisco:unified_ip_phone_7911g:*:*:*:*:*:*:*:*
cpe:2.3:h:cisco:unified_ip_phone_7931g:*:*:*:*:*:*:*:*
cpe:2.3:h:cisco:unified_ip_phone_7941g:*:*:*:*:*:*:*:*
cpe:2.3:h:cisco:unified_ip_phone_7941g-ge:*:*:*:*:*:*:*:*
cpe:2.3:h:cisco:unified_ip_phone_7942g:*:*:*:*:*:*:*:*
cpe:2.3:h:cisco:unified_ip_phone_7945g:*:*:*:*:*:*:*:*
cpe:2.3:h:cisco:unified_ip_phone_7961g:*:*:*:*:*:*:*:*
cpe:2.3:h:cisco:unified_ip_phone_7961g-ge:*:*:*:*:*:*:*:*
cpe:2.3:h:cisco:unified_ip_phone_7962g:*:*:*:*:*:*:*:*
cpe:2.3:h:cisco:unified_ip_phone_7965g:*:*:*:*:*:*:*:*
cpe:2.3:h:cisco:unified_ip_phone_7970g:*:*:*:*:*:*:*:*
cpe:2.3:h:cisco:unified_ip_phone_7971g-ge:*:*:*:*:*:*:*:*
cpe:2.3:h:cisco:unified_ip_phone_7975g:*:*:*:*:*:*:*:*
cpe:2.3:o:cisco:skinny_client_control_protocol_software:*:sr1:*:*:*:*:*:* 9.1\(1\) (including)