The kernel in Cisco Native Unix (CNU) on Cisco Unified IP Phone 7900 series devices (aka TNP phones) with software before 9.3.1-ES10 does not properly validate unspecified system calls, which allows attackers to execute arbitrary code or cause a denial of service (memory overwrite) via a crafted binary.
The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Skinny_client_control_protocol_software | Cisco | * | 9.2(4) (including) |
Skinny_client_control_protocol_software | Cisco | 1.0(1) (including) | 1.0(1) (including) |
Skinny_client_control_protocol_software | Cisco | 1.0(2) (including) | 1.0(2) (including) |
Skinny_client_control_protocol_software | Cisco | 1.0(2)-sr1 (including) | 1.0(2)-sr1 (including) |
Skinny_client_control_protocol_software | Cisco | 1.0(3) (including) | 1.0(3) (including) |
Skinny_client_control_protocol_software | Cisco | 1.0(4) (including) | 1.0(4) (including) |
Skinny_client_control_protocol_software | Cisco | 1.0(5) (including) | 1.0(5) (including) |
Skinny_client_control_protocol_software | Cisco | 1.0(9) (including) | 1.0(9) (including) |
Skinny_client_control_protocol_software | Cisco | 1.1(1) (including) | 1.1(1) (including) |
Skinny_client_control_protocol_software | Cisco | 1.2(1) (including) | 1.2(1) (including) |
Skinny_client_control_protocol_software | Cisco | 1.3(1) (including) | 1.3(1) (including) |
Skinny_client_control_protocol_software | Cisco | 1.3(2) (including) | 1.3(2) (including) |
Skinny_client_control_protocol_software | Cisco | 1.3(3) (including) | 1.3(3) (including) |
Skinny_client_control_protocol_software | Cisco | 1.3(4) (including) | 1.3(4) (including) |
Skinny_client_control_protocol_software | Cisco | 1.3(4)-sr1 (including) | 1.3(4)-sr1 (including) |
Skinny_client_control_protocol_software | Cisco | 1.4(1) (including) | 1.4(1) (including) |
Skinny_client_control_protocol_software | Cisco | 1.4(2) (including) | 1.4(2) (including) |
Skinny_client_control_protocol_software | Cisco | 2.0(0) (including) | 2.0(0) (including) |
Skinny_client_control_protocol_software | Cisco | 2.0(1) (including) | 2.0(1) (including) |
Skinny_client_control_protocol_software | Cisco | 3.0 (including) | 3.0 (including) |
Skinny_client_control_protocol_software | Cisco | 3.0(0) (including) | 3.0(0) (including) |
Skinny_client_control_protocol_software | Cisco | 3.0(1) (including) | 3.0(1) (including) |
Skinny_client_control_protocol_software | Cisco | 3.0(2) (including) | 3.0(2) (including) |
Skinny_client_control_protocol_software | Cisco | 3.1 (including) | 3.1 (including) |
Skinny_client_control_protocol_software | Cisco | 3.1(1) (including) | 3.1(1) (including) |
Skinny_client_control_protocol_software | Cisco | 3.1(2) (including) | 3.1(2) (including) |
Skinny_client_control_protocol_software | Cisco | 3.1(3) (including) | 3.1(3) (including) |
Skinny_client_control_protocol_software | Cisco | 3.1(4) (including) | 3.1(4) (including) |
Skinny_client_control_protocol_software | Cisco | 3.1(6) (including) | 3.1(6) (including) |
Skinny_client_control_protocol_software | Cisco | 3.1(10) (including) | 3.1(10) (including) |
Skinny_client_control_protocol_software | Cisco | 3.1(11) (including) | 3.1(11) (including) |
Skinny_client_control_protocol_software | Cisco | 3.2 (including) | 3.2 (including) |
Skinny_client_control_protocol_software | Cisco | 3.2(1) (including) | 3.2(1) (including) |
Skinny_client_control_protocol_software | Cisco | 3.2(2) (including) | 3.2(2) (including) |
Skinny_client_control_protocol_software | Cisco | 3.2(3) (including) | 3.2(3) (including) |
Skinny_client_control_protocol_software | Cisco | 3.2(4) (including) | 3.2(4) (including) |
Skinny_client_control_protocol_software | Cisco | 3.2(5) (including) | 3.2(5) (including) |
Skinny_client_control_protocol_software | Cisco | 3.2(6) (including) | 3.2(6) (including) |
Skinny_client_control_protocol_software | Cisco | 3.2(6a) (including) | 3.2(6a) (including) |
Skinny_client_control_protocol_software | Cisco | 3.2(7) (including) | 3.2(7) (including) |
Skinny_client_control_protocol_software | Cisco | 3.2(8) (including) | 3.2(8) (including) |
Skinny_client_control_protocol_software | Cisco | 3.2(9) (including) | 3.2(9) (including) |
Skinny_client_control_protocol_software | Cisco | 3.2(10) (including) | 3.2(10) (including) |
Skinny_client_control_protocol_software | Cisco | 3.2(11) (including) | 3.2(11) (including) |
Skinny_client_control_protocol_software | Cisco | 3.2(12) (including) | 3.2(12) (including) |
Skinny_client_control_protocol_software | Cisco | 3.2(13) (including) | 3.2(13) (including) |
Skinny_client_control_protocol_software | Cisco | 3.2(14) (including) | 3.2(14) (including) |
Skinny_client_control_protocol_software | Cisco | 3.2(15) (including) | 3.2(15) (including) |
Skinny_client_control_protocol_software | Cisco | 3.3(2) (including) | 3.3(2) (including) |
Skinny_client_control_protocol_software | Cisco | 3.3(3) (including) | 3.3(3) (including) |
Skinny_client_control_protocol_software | Cisco | 3.3(4) (including) | 3.3(4) (including) |
Skinny_client_control_protocol_software | Cisco | 3.3(5) (including) | 3.3(5) (including) |
Skinny_client_control_protocol_software | Cisco | 3.3(6) (including) | 3.3(6) (including) |
Skinny_client_control_protocol_software | Cisco | 3.3(7) (including) | 3.3(7) (including) |
Skinny_client_control_protocol_software | Cisco | 3.3(8) (including) | 3.3(8) (including) |
Skinny_client_control_protocol_software | Cisco | 3.3(9) (including) | 3.3(9) (including) |
Skinny_client_control_protocol_software | Cisco | 3.3(10) (including) | 3.3(10) (including) |
Skinny_client_control_protocol_software | Cisco | 3.3(11) (including) | 3.3(11) (including) |
Skinny_client_control_protocol_software | Cisco | 3.3(12) (including) | 3.3(12) (including) |
Skinny_client_control_protocol_software | Cisco | 3.3(13) (including) | 3.3(13) (including) |
Skinny_client_control_protocol_software | Cisco | 3.3(14) (including) | 3.3(14) (including) |
Skinny_client_control_protocol_software | Cisco | 3.3(15) (including) | 3.3(15) (including) |
Skinny_client_control_protocol_software | Cisco | 3.3(16) (including) | 3.3(16) (including) |
Skinny_client_control_protocol_software | Cisco | 3.3(20) (including) | 3.3(20) (including) |
Skinny_client_control_protocol_software | Cisco | 4.0(0) (including) | 4.0(0) (including) |
Skinny_client_control_protocol_software | Cisco | 4.1(2) (including) | 4.1(2) (including) |
Skinny_client_control_protocol_software | Cisco | 4.1(3) (including) | 4.1(3) (including) |
Skinny_client_control_protocol_software | Cisco | 4.1(4) (including) | 4.1(4) (including) |
Skinny_client_control_protocol_software | Cisco | 4.1(5) (including) | 4.1(5) (including) |
Skinny_client_control_protocol_software | Cisco | 4.1(6) (including) | 4.1(6) (including) |
Skinny_client_control_protocol_software | Cisco | 4.1(7) (including) | 4.1(7) (including) |
Skinny_client_control_protocol_software | Cisco | 5.0(0) (including) | 5.0(0) (including) |
Skinny_client_control_protocol_software | Cisco | 5.0(1a) (including) | 5.0(1a) (including) |
Skinny_client_control_protocol_software | Cisco | 5.0(3) (including) | 5.0(3) (including) |
Skinny_client_control_protocol_software | Cisco | 5.0(5) (including) | 5.0(5) (including) |
Skinny_client_control_protocol_software | Cisco | 5.0(6) (including) | 5.0(6) (including) |
Skinny_client_control_protocol_software | Cisco | 5.0(7) (including) | 5.0(7) (including) |
Skinny_client_control_protocol_software | Cisco | 6.0(0) (including) | 6.0(0) (including) |
Skinny_client_control_protocol_software | Cisco | 6.0(2)-sr2 (including) | 6.0(2)-sr2 (including) |
Skinny_client_control_protocol_software | Cisco | 6.0(3) (including) | 6.0(3) (including) |
Skinny_client_control_protocol_software | Cisco | 6.0(3)-sr1 (including) | 6.0(3)-sr1 (including) |
Skinny_client_control_protocol_software | Cisco | 6.0(4) (including) | 6.0(4) (including) |
Skinny_client_control_protocol_software | Cisco | 6.0(5) (including) | 6.0(5) (including) |
Skinny_client_control_protocol_software | Cisco | 6.1(0) (including) | 6.1(0) (including) |
Skinny_client_control_protocol_software | Cisco | 6.1(1) (including) | 6.1(1) (including) |
Skinny_client_control_protocol_software | Cisco | 7.0(1) (including) | 7.0(1) (including) |
Skinny_client_control_protocol_software | Cisco | 7.0(2) (including) | 7.0(2) (including) |
Skinny_client_control_protocol_software | Cisco | 7.0(2)-sr1 (including) | 7.0(2)-sr1 (including) |
Skinny_client_control_protocol_software | Cisco | 7.0(3) (including) | 7.0(3) (including) |
Skinny_client_control_protocol_software | Cisco | 7.1(2) (including) | 7.1(2) (including) |
Skinny_client_control_protocol_software | Cisco | 7.2(2) (including) | 7.2(2) (including) |
Skinny_client_control_protocol_software | Cisco | 7.2(3) (including) | 7.2(3) (including) |
Skinny_client_control_protocol_software | Cisco | 7.2(4) (including) | 7.2(4) (including) |
Skinny_client_control_protocol_software | Cisco | 8.0(1) (including) | 8.0(1) (including) |
Skinny_client_control_protocol_software | Cisco | 8.0(2) (including) | 8.0(2) (including) |
Skinny_client_control_protocol_software | Cisco | 8.0(3) (including) | 8.0(3) (including) |
Skinny_client_control_protocol_software | Cisco | 8.0(4) (including) | 8.0(4) (including) |
Skinny_client_control_protocol_software | Cisco | 8.0(4)-sr1 (including) | 8.0(4)-sr1 (including) |
Skinny_client_control_protocol_software | Cisco | 8.0(4)-sr3a (including) | 8.0(4)-sr3a (including) |
Skinny_client_control_protocol_software | Cisco | 8.0(5) (including) | 8.0(5) (including) |
Skinny_client_control_protocol_software | Cisco | 8.0(6) (including) | 8.0(6) (including) |
Skinny_client_control_protocol_software | Cisco | 8.0(7) (including) | 8.0(7) (including) |
Skinny_client_control_protocol_software | Cisco | 8.0(8) (including) | 8.0(8) (including) |
Skinny_client_control_protocol_software | Cisco | 8.0(9) (including) | 8.0(9) (including) |
Skinny_client_control_protocol_software | Cisco | 8.0(10) (including) | 8.0(10) (including) |
Skinny_client_control_protocol_software | Cisco | 8.1(1) (including) | 8.1(1) (including) |
Skinny_client_control_protocol_software | Cisco | 8.1(2) (including) | 8.1(2) (including) |
Skinny_client_control_protocol_software | Cisco | 8.2(1) (including) | 8.2(1) (including) |
Skinny_client_control_protocol_software | Cisco | 8.2(2)-sr1 (including) | 8.2(2)-sr1 (including) |
Skinny_client_control_protocol_software | Cisco | 8.2(2)-sr2 (including) | 8.2(2)-sr2 (including) |
Skinny_client_control_protocol_software | Cisco | 8.2(2)-sr3 (including) | 8.2(2)-sr3 (including) |
Skinny_client_control_protocol_software | Cisco | 8.2(2)-sr4 (including) | 8.2(2)-sr4 (including) |
Skinny_client_control_protocol_software | Cisco | 8.3(1) (including) | 8.3(1) (including) |
Skinny_client_control_protocol_software | Cisco | 8.3(2) (including) | 8.3(2) (including) |
Skinny_client_control_protocol_software | Cisco | 8.3(2)-sr1 (including) | 8.3(2)-sr1 (including) |
Skinny_client_control_protocol_software | Cisco | 8.3(3) (including) | 8.3(3) (including) |
Skinny_client_control_protocol_software | Cisco | 8.3(3)-sr1 (including) | 8.3(3)-sr1 (including) |
Skinny_client_control_protocol_software | Cisco | 8.3(3)-sr2 (including) | 8.3(3)-sr2 (including) |
Skinny_client_control_protocol_software | Cisco | 8.3(5) (including) | 8.3(5) (including) |
Skinny_client_control_protocol_software | Cisco | 8.4(1) (including) | 8.4(1) (including) |
Skinny_client_control_protocol_software | Cisco | 8.4(1)-sr2 (including) | 8.4(1)-sr2 (including) |
Skinny_client_control_protocol_software | Cisco | 8.4(2) (including) | 8.4(2) (including) |
Skinny_client_control_protocol_software | Cisco | 8.4(3) (including) | 8.4(3) (including) |
Skinny_client_control_protocol_software | Cisco | 8.4(4) (including) | 8.4(4) (including) |
Skinny_client_control_protocol_software | Cisco | 8.5(2) (including) | 8.5(2) (including) |
Skinny_client_control_protocol_software | Cisco | 8.5(2)-sr1 (including) | 8.5(2)-sr1 (including) |
Skinny_client_control_protocol_software | Cisco | 8.5(3) (including) | 8.5(3) (including) |
Skinny_client_control_protocol_software | Cisco | 8.5(3)-sr1 (including) | 8.5(3)-sr1 (including) |
Skinny_client_control_protocol_software | Cisco | 8.5(4) (including) | 8.5(4) (including) |
Skinny_client_control_protocol_software | Cisco | 8.70 (including) | 8.70 (including) |
Skinny_client_control_protocol_software | Cisco | 9.0(2)-sr1 (including) | 9.0(2)-sr1 (including) |
Skinny_client_control_protocol_software | Cisco | 9.0(2)-sr2 (including) | 9.0(2)-sr2 (including) |
Skinny_client_control_protocol_software | Cisco | 9.0(3) (including) | 9.0(3) (including) |
Skinny_client_control_protocol_software | Cisco | 9.0(3b) (including) | 9.0(3b) (including) |
Skinny_client_control_protocol_software | Cisco | 9.1(1) (including) | 9.1(1) (including) |
Skinny_client_control_protocol_software | Cisco | 9.1(1)-sr1 (including) | 9.1(1)-sr1 (including) |
Skinny_client_control_protocol_software | Cisco | 9.1(1)-sr2 (including) | 9.1(1)-sr2 (including) |
Skinny_client_control_protocol_software | Cisco | 9.2(1) (including) | 9.2(1) (including) |
Skinny_client_control_protocol_software | Cisco | 9.2(2) (including) | 9.2(2) (including) |
Input validation is a frequently-used technique for checking potentially dangerous inputs in order to ensure that the inputs are safe for processing within the code, or when communicating with other components. Input can consist of:
Data can be simple or structured. Structured data can be composed of many nested layers, composed of combinations of metadata and raw data, with other simple or structured data. Many properties of raw data or metadata may need to be validated upon entry into the code, such as:
Implied or derived properties of data must often be calculated or inferred by the code itself. Errors in deriving properties may be considered a contributing factor to improper input validation.