← Vulnerability feed

Vulnerability record · CVE-2011-1603 · published 2 June 2011

CVE-2011-1603: Cisco unified ip phone 7906 permissions and access controls vulnerability

Cisco · Unified Ip Phone 7906

Cisco Unified IP Phones 7900 devices (aka TNP phones) with software before 9.2.1 allow local users to gain privileges via unspecified vectors, aka Bug ID CSCtn65815.

6.6 CVSS 2.0 Medium EPSS 0.26% · top 83.6% CWE-264 · Permissions and access controls
6.6CVSS 2.0 base score
0.26%EPSS exploitation probability, 30 days
NoNot in CISA KEV
15Affected product versions listed by NVD
10References
16 Jun 2026Last modified by NVD

Description

Cisco Unified IP Phones 7900 devices (aka TNP phones) with software before 9.2.1 allow local users to gain privileges via unspecified vectors, aka Bug ID CSCtn65815.

AV:L/AC:M/Au:S/C:C/I:C/A:C

Affected products

15 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2011-1603 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

6.8CVE-2012-5445Cisco skinny client control protocol software improper input validation vulnerabilityThe kernel in Cisco Native Unix (CNU) on Cisco Unified IP Phone 7900 series devices (aka TNP phones) with software before 9.3.1-ES10 does not properl…EPSS 0.40%6.6CVE-2011-1602Cisco unified ip phone 7906 permissions and access controls vulnerabilityThe su utility on Cisco Unified IP Phones 7900 devices (aka TNP phones) with software before 9.0.3 allows local users to gain privileges via unspecif…EPSS 0.26%6.4CVE-2002-0882Cisco voip phone cp-7940 vulnerabilityThe web server for Cisco IP Phone (VoIP) models 7910, 7940, and 7960 allows remote attackers to cause a denial of service (reset) and possibly read s…EPSS 2.7%6.1CVE-2018-15434Cisco skinny client control protocol software cross-site scripting vulnerabilityA vulnerability in the web-based management interface of Cisco Unified IP Phone 7900 Series could allow an unauthenticated, remote attacker to conduc…EPSS 0.92%5.0CVE-2002-0880Cisco voip phone cp-7940 vulnerabilityCisco IP Phone (VoIP) models 7910, 7940, and 7960 allow remote attackers to cause a denial of service (crash) via malformed packets as demonstrated b…EPSS 1.3%2.1CVE-2002-0881Cisco voip phone cp-7940 vulnerabilityCisco IP Phone (VoIP) models 7910, 7940, and 7960 use a default administrative password, which allows attackers with physical access to the phone to …EPSS 0.39%1.5CVE-2011-1637Cisco unified ip phone 7906 permissions and access controls vulnerabilityCisco Unified IP Phones 7900 devices (aka TNP phones) with software before 9.2.1 do not properly verify signatures for software images, which allows …EPSS 0.27%5.1CVE-2015-3246libuser userhelper direct /etc/passwd write race conditionlibuser before 0.56.13-8 and 0.60 before 0.60-7, as used by the userhelper program in the usermode package, modifies /etc/passwd directly instead of …KEVEPSS 8.8%analysed

Source: NIST National Vulnerability Database (record CVE-2011-1603), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.