Evidence dossier

CVE-2020-3161

Cisco IP Phones Web Server Remote Code Execution and Denial of Service Vulnerability

Exploited in the wild (CISA KEV since Nov 3, 2021). NVD reports CVSS 3.1 9.8. EPSS estimates 83.9% exploit likelihood as of Aug 26, 2026.

89.790.5Priority evidence range
Evidence current through Aug 27, 2026, 6:09 PM UTC

As of Aug 27, 2026

Normalized restatement

A vulnerability in the web server for Cisco IP Phones could allow an unauthenticated, remote attacker to execute code with root privileges or cause a reload of an affected IP phone, resulting in a denial of service (DoS) condition. The vulnerability is due to a lack of proper input validation of HTTP requests. An attacker could exploit this vulnerability by sending a crafted HTTP request to the web server of a targeted device. A successful exploit could allow the attacker to remotely execute code with root privileges or cause a reload of an affected IP phone, resulting in a DoS condition.

State
PUBLISHED
Published
Apr 15, 2020
Updated
Oct 21, 2025
Evidence coverage
99%

Evidence chronology

What was known when

Download this view's receipt →
  1. Source dateSource date omittedFirst observed by CASCA
    CISA-ADP

    Record text: CISA ADP Vulnrichment

    Inspect raw assertion
    Field
    container
    Value
    CISA ADP Vulnrichment
    Original evidence ↗
  2. Source dateSource date omittedFirst observed by CASCA
    cisco

    Record text: Cisco IP Phones Web Server Remote Code Execution and Denial of Service Vulnerability

    Inspect raw assertion
    Field
    container
    Value
    Cisco IP Phones Web Server Remote Code Execution and Denial of Service Vulnerability
    Original evidence ↗
  3. Source dateSource date omittedFirst observed by CASCA
    CVE Program

    Record text: CVE Program Container

    Inspect raw assertion
    Field
    container
    Value
    CVE Program Container
    Original evidence ↗
  4. Source dateFirst observed by CASCA
    CISA KEV

    Exploitation cataloged: Cisco IP Phones Web Server Remote Code Execution and Denial-of-Service Vulnerability

    Inspect raw assertion
    Field
    observed_exploitation
    Value
    Cisco IP Phones Web Server Remote Code Execution and Denial-of-Service Vulnerability
    Original evidence ↗
  5. Source dateFirst observed by CASCA
    FIRST EPSS

    EPSS score: 83.86% probability · 99.67th percentile

    Inspect raw assertion
    Field
    model_probability
    Value
    Probability 0.838550000000; percentile 0.996700000000
    Original evidence ↗
ExploitationCatalog member

CISA KEV · catalog date Nov 3, 2021 · first observed Jul 19, 2026

Exploit likelihood83.86%

FIRST EPSS · score date Aug 26, 2026 · 99.7th percentile · first observed Aug 26, 2026

SeverityCVSS 9.8

NVD · CVSS 3.1 · first observed Jul 19, 2026 · same-version scores align in this snapshot

Evidence detail

Source limits and decisions

Why each evidence state has this value

casca-unknown-reasons-v1
Exploitation statusEvidence supported

Eligible evidence is present for this bounded claim.

Revision
evidence-policy-v1.1.0
Cutoff
Aug 27, 2026
Resolution
None
Exploit likelihoodEvidence supported

Eligible evidence is present for this bounded claim.

Revision
evidence-policy-v1.1.0
Cutoff
Aug 27, 2026
Resolution
None
Severity assessmentEvidence supported

Eligible evidence is present for this bounded claim.

Revision
casca-direct-cvss-eligibility-v1
Cutoff
Aug 27, 2026
Resolution
None
Affected productsSource-reported scope

The cited source assertion is retained while canonical product linkage remains open.

Revision
casca-factor-d-obligations-v1
Cutoff
Aug 27, 2026
Resolution
Resolve identity

Source comparison

Who said what

CISA-ADPIndependent enrichment
Record text

CISA ADP Vulnrichment

Inspect raw assertion
Field
container
Value
CISA ADP Vulnrichment
Source dateSource date omittedFirst observed by CASCAOriginal evidence ↗
ciscoOriginal assertion
Record text

Cisco IP Phones Web Server Remote Code Execution and Denial of Service Vulnerability

Inspect raw assertion
Field
container
Value
Cisco IP Phones Web Server Remote Code Execution and Denial of Service Vulnerability
Source dateSource date omittedFirst observed by CASCAOriginal evidence ↗
CVE ProgramDerivative copy
Record text

CVE Program Container

Inspect raw assertion
Field
container
Value
CVE Program Container
Source dateSource date omittedFirst observed by CASCAOriginal evidence ↗
CISA KEVOriginal assertion
Exploitation cataloged

Cisco IP Phones Web Server Remote Code Execution and Denial-of-Service Vulnerability

Inspect raw assertion
Field
observed_exploitation
Value
Cisco IP Phones Web Server Remote Code Execution and Denial-of-Service Vulnerability
Source dateFirst observed by CASCAOriginal evidence ↗
FIRST EPSSOriginal assertion
EPSS score

83.86% probability · 99.67th percentile

Inspect raw assertion
Field
model_probability
Value
Probability 0.838550000000; percentile 0.996700000000
Source dateFirst observed by CASCAOriginal evidence ↗

Applicability

Cited product scope

Trace impact →
44Underlying assertions
26Canonical products
31Target assertions
13Constraint assertions

Grouped from 26 configuration nodes in this exact snapshot. Visual grouping is navigational; asset exposure and root cause require cited evidence.

Identity source boundaries
  • Cpe dictionary1,775,266 records · observed through 2026-07-21T06:45:29.809Z27d65b0f-b718-4b4f-bb79-c47c68d09dfa
  • Cpe match643,502 records · observed through 2026-07-21T08:13:17.697Z955dae73-7302-438b-aee1-058d7cc5d48e

27 scope groups

cisco · source assertedCiscoCisco IP phoneDirect source scope
Affected: n/a
Source-reported scope

Canonical linkage remains open; the cited source assertion is retained below.

Inspect raw assertion[{"status": "affected", "version": "n/a"}]
NVD CPE · HARDWAREcisco8831Environmental constraint · 1 assertions
Version not applicableCanonical identity product-7ddc82bc9610f46f477c785d17642e700e7032d2b41f233360b14707ddfef610Linked exact
Scope constrained
Inspect raw assertion
  1. cpe:2.3:h:cisco:8831:-:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Environmental constraint
    Configuration
    12 · node/1 · match 0
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    be2514a1-486c-40f7-8746-56e2b973cbe6
NVD CPE · OPERATING SYSTEMcisco8831_firmwareVulnerable target · 3 assertions
Version 10.3(1)es14; Version 11.0(1); Version 11.0(5)sr1Canonical identity product-33ba62de716df894763e95d4d96f230c752266159800cc8c2a9a9b8b529c8852Linked exact
Scope supported
Inspect raw assertions
  1. cpe:2.3:o:cisco:8831_firmware:11.0\(1\):*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    12 · node/0 · match 1
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    188db874-2611-4919-a2e0-a955852ab424
  2. cpe:2.3:o:cisco:8831_firmware:10.3\(1\)es14:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    12 · node/0 · match 0
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    9f731586-5715-45fa-ab4d-7301d15dfb60
  3. cpe:2.3:o:cisco:8831_firmware:11.0\(5\)sr1:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    12 · node/0 · match 2
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    dad76aab-7fd9-4f31-87c2-899128a1943e
NVD CPE · HARDWAREciscoip_phone_7811Environmental constraint · 1 assertions
Version not applicableCanonical identity product-7dcd0d1fd3e497fae2f230dba61273635103f05072dd95b30bab2b7b89dfe6efLinked exact
Scope constrained
Inspect raw assertion
  1. cpe:2.3:h:cisco:ip_phone_7811:-:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Environmental constraint
    Configuration
    9 · node/1 · match 0
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    d7260c17-7067-47ad-995f-366a5e8b10e7
NVD CPE · OPERATING SYSTEMciscoip_phone_7811_firmwareVulnerable target · 1 assertions
Version 11.0(1)Canonical identity product-e2c44e24b591b7f8e13b802c05b8bc4eacdb24f46ac11fa4f86f7d18e16ee25bLinked exact
Scope supported
Inspect raw assertion
  1. cpe:2.3:o:cisco:ip_phone_7811_firmware:11.0\(1\):*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    9 · node/0 · match 0
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    6d715bdd-d977-4581-ba09-a2936991cfa7
NVD CPE · HARDWAREciscoip_phone_7821Environmental constraint · 1 assertions
Version not applicableCanonical identity product-fa478dd841947879886f7853e658163723b5aaace7f32396814ab34310d275adLinked exact
Scope constrained
Inspect raw assertion
  1. cpe:2.3:h:cisco:ip_phone_7821:-:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Environmental constraint
    Configuration
    3 · node/1 · match 0
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    ae7afff0-5b21-400b-b923-e9b7fcce08fa
NVD CPE · OPERATING SYSTEMciscoip_phone_7821_firmwareVulnerable target · 1 assertions
Version 11.0(1)Canonical identity product-61ff42227fd1af35ac0340b3c9128940af6d86d72d6293e3393aa857f9f4489dLinked exact
Scope supported
Inspect raw assertion
  1. cpe:2.3:o:cisco:ip_phone_7821_firmware:11.0\(1\):*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    3 · node/0 · match 0
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    b552853a-14e0-4339-a87e-7ae00bf143ea
NVD CPE · HARDWAREciscoip_phone_7841Environmental constraint · 1 assertions
Version not applicableCanonical identity product-bd9358687818bbc4ac3fa9da6f3e608666442bae0905d68457417d6136c37458Linked exact
Scope constrained
Inspect raw assertion
  1. cpe:2.3:h:cisco:ip_phone_7841:-:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Environmental constraint
    Configuration
    2 · node/1 · match 0
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    73cf8a50-11bd-4506-bf2a-cca36bf59eff
NVD CPE · OPERATING SYSTEMciscoip_phone_7841_firmwareVulnerable target · 1 assertions
Version 11.0(1)Canonical identity product-411b33c5e276ef0c39aa596afe050d64dabb2baa11d52bfeeedefcf7dcc29913Linked exact
Scope supported
Inspect raw assertion
  1. cpe:2.3:o:cisco:ip_phone_7841_firmware:11.0\(1\):*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    2 · node/0 · match 0
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    1617d281-505f-49d2-aaab-91d61f7d4797
NVD CPE · HARDWAREciscoip_phone_7861Environmental constraint · 1 assertions
Version not applicableCanonical identity product-ac75d9aca38facb798b308af3deda8bf3d460fb32264f839f365171f0ec885b1Linked exact
Scope constrained
Inspect raw assertion
  1. cpe:2.3:h:cisco:ip_phone_7861:-:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Environmental constraint
    Configuration
    7 · node/1 · match 0
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    e52c420c-fd54-4be4-8720-e05307d53520
NVD CPE · OPERATING SYSTEMciscoip_phone_7861_firmwareVulnerable target · 1 assertions
Version 11.0(1)Canonical identity product-d47a44eb1ce067a1ef304472bf6e705298521f0e8d78e702c9ae41f524eaf3a9Linked exact
Scope supported
Inspect raw assertion
  1. cpe:2.3:o:cisco:ip_phone_7861_firmware:11.0\(1\):*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    7 · node/0 · match 0
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    5e2460c9-f9c8-4436-bd8e-3fdd8978e8c8
NVD CPE · HARDWAREciscoip_phone_8811Environmental constraint · 1 assertions
Version not applicableCanonical identity product-1e46f9ea9013f8951285c16221b08fa3145f154da36937b7f67f53648e3ff8cbLinked exact
Scope constrained
Inspect raw assertion
  1. cpe:2.3:h:cisco:ip_phone_8811:-:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Environmental constraint
    Configuration
    4 · node/1 · match 0
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    d0cc3127-3152-4906-9fe0-bc6f21dcadaa
NVD CPE · OPERATING SYSTEMciscoip_phone_8811_firmwareVulnerable target · 3 assertions
Version 10.3(1)es14; Version 11.0(1); Version 11.0(5)sr1Canonical identity product-8d6a2a63a0314eb6c4115bf298817704e04c9db4b4387d8c3906cc89cca85a51Linked exact
Scope supported
Inspect raw assertions
  1. cpe:2.3:o:cisco:ip_phone_8811_firmware:11.0\(1\):*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    4 · node/0 · match 1
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    2404681b-34f2-4f60-ae8b-1a41e2fcfb68
  2. cpe:2.3:o:cisco:ip_phone_8811_firmware:10.3\(1\)es14:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    4 · node/0 · match 0
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    8260121f-1819-40ed-a3cc-86a98b84cf13
  3. cpe:2.3:o:cisco:ip_phone_8811_firmware:11.0\(5\)sr1:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    4 · node/0 · match 2
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    d7bde345-b411-4a8b-a6a6-a031c52e2844
NVD CPE · HARDWAREciscoip_phone_8821Environmental constraint · 1 assertions
Version not applicableCanonical identity product-d9ee130677e5cd5d9685201244cce62fe034f894a1516ec9dbe1f026de4a9e90Linked exact
Scope constrained
Inspect raw assertion
  1. cpe:2.3:h:cisco:ip_phone_8821:-:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Environmental constraint
    Configuration
    10 · node/1 · match 0
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    36c99e0b-0383-4cb3-b325-ec0f3d57d39d
NVD CPE · HARDWAREciscoip_phone_8821-exEnvironmental constraint · 1 assertions
Version not applicableCanonical identity product-ca620159ad9c7fcc69b06144055b108acf007a9197489f2c6f7c758aa744e3ccLinked exact
Scope constrained
Inspect raw assertion
  1. cpe:2.3:h:cisco:ip_phone_8821-ex:-:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Environmental constraint
    Configuration
    11 · node/1 · match 0
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    ee56b858-b59d-4197-9b2a-33a03908b967
NVD CPE · OPERATING SYSTEMciscoip_phone_8821-ex_firmwareVulnerable target · 3 assertions
Version 10.3(1)es14; Version 11.0(1); Version 11.0(5)sr1Canonical identity product-cf6c91411318ebba7fc0b59bdb1c39db79dba82ec543fe6db9c28f73dc96bccfLinked exact
Scope supported
Inspect raw assertions
  1. cpe:2.3:o:cisco:ip_phone_8821-ex_firmware:11.0\(1\):*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    11 · node/0 · match 1
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    ffc9fab0-b9a7-476a-aaf0-a4b14fc48cf2
  2. cpe:2.3:o:cisco:ip_phone_8821-ex_firmware:11.0\(5\)sr1:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    11 · node/0 · match 2
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    e6745422-3ce4-41a0-a87e-bd9c5da45bf2
  3. cpe:2.3:o:cisco:ip_phone_8821-ex_firmware:10.3\(1\)es14:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    11 · node/0 · match 0
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    a3783ae8-6b80-4dc4-8525-84e63d50daac
NVD CPE · OPERATING SYSTEMciscoip_phone_8821_firmwareVulnerable target · 3 assertions
Version 10.3(1)es14; Version 11.0(1); Version 11.0(5)sr1Canonical identity product-42c15c017be5a6ff16425a95f494b03419e1f748f3c7a760e307c317447cf4ffLinked exact
Scope supported
Inspect raw assertions
  1. cpe:2.3:o:cisco:ip_phone_8821_firmware:11.0\(1\):*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    10 · node/0 · match 1
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    9e4622ef-d5ca-4971-a3a7-0610c136f160
  2. cpe:2.3:o:cisco:ip_phone_8821_firmware:11.0\(5\)sr1:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    10 · node/0 · match 2
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    2740b39b-add1-4cd9-bef8-ffbdea1567f0
  3. cpe:2.3:o:cisco:ip_phone_8821_firmware:10.3\(1\)es14:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    10 · node/0 · match 0
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    aa6858d1-20bc-417a-9328-196798a23b48
NVD CPE · HARDWAREciscoip_phone_8841Environmental constraint · 1 assertions
Version not applicableCanonical identity product-77d31b9c89b59019122761272223204b0eaa6a8bfd63800dabd7d37a8f09166fLinked exact
Scope constrained
Inspect raw assertion
  1. cpe:2.3:h:cisco:ip_phone_8841:-:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Environmental constraint
    Configuration
    8 · node/1 · match 0
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    7944cc9c-ae08-4f30-af65-134dadbd0fa1
NVD CPE · OPERATING SYSTEMciscoip_phone_8841_firmwareVulnerable target · 3 assertions
Version 10.3(1)es14; Version 11.0(1); Version 11.0(5)sr1Canonical identity product-837b408c7aa1479d0484790e5e6abe022af11c7c443080843578e88396eef0f2Linked exact
Scope supported
Inspect raw assertions
  1. cpe:2.3:o:cisco:ip_phone_8841_firmware:11.0\(5\)sr1:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    8 · node/0 · match 2
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    6528a512-7359-4f95-9bd4-0083524f9125
  2. cpe:2.3:o:cisco:ip_phone_8841_firmware:11.0\(1\):*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    8 · node/0 · match 1
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    e719fd30-98c0-4582-8ed5-ddba01ccc055
  3. cpe:2.3:o:cisco:ip_phone_8841_firmware:10.3\(1\)es14:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    8 · node/0 · match 0
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    b73d3cf0-e2a3-4a76-82d8-3c899b41ba11
NVD CPE · HARDWAREciscoip_phone_8845Environmental constraint · 1 assertions
Version not applicableCanonical identity product-75cf323c2c642461d504f0f07a020be765bc8763103a41b6b4c5c3c44b8de988Linked exact
Scope constrained
Inspect raw assertion
  1. cpe:2.3:h:cisco:ip_phone_8845:-:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Environmental constraint
    Configuration
    6 · node/1 · match 0
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    a313e64a-f43c-4fba-a389-6171cbd709c0
NVD CPE · OPERATING SYSTEMciscoip_phone_8845_firmwareVulnerable target · 3 assertions
Version 10.3(1)es14; Version 11.0(1); Version 11.0(5)sr1Canonical identity product-1fdf650c2a323d9c04c19edf1f15ef4b8ce264411264a77973eb5b42248103feLinked exact
Scope supported
Inspect raw assertions
  1. cpe:2.3:o:cisco:ip_phone_8845_firmware:11.0\(1\):*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    6 · node/0 · match 1
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    b41e93db-62e6-4afb-8c72-44c51e1cb1e7
  2. cpe:2.3:o:cisco:ip_phone_8845_firmware:11.0\(5\)sr1:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    6 · node/0 · match 2
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    16218f2f-0889-437d-a8c4-efc7c197c19a
  3. cpe:2.3:o:cisco:ip_phone_8845_firmware:10.3\(1\)es14:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    6 · node/0 · match 0
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    363e47b4-e22b-4a8a-92cd-1acdb2cf6cd5
NVD CPE · HARDWAREciscoip_phone_8851Environmental constraint · 1 assertions
Version not applicableCanonical identity product-9ec20552fdcbf7db5e37be0185b70577ece563b8e257f3a4a03876950b67fab0Linked exact
Scope constrained
Inspect raw assertion
  1. cpe:2.3:h:cisco:ip_phone_8851:-:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Environmental constraint
    Configuration
    1 · node/1 · match 0
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    8af6dc5e-f582-445e-bf05-2d55a0954663
NVD CPE · OPERATING SYSTEMciscoip_phone_8851_firmwareVulnerable target · 3 assertions
Version 10.3(1)es14; Version 11.0(1); Version 11.0(5)sr1Canonical identity product-b14957199e4d341bce8e57b17bce50f294753fb58288cbe9cdd2c9d1e03c116cLinked exact
Scope supported
Inspect raw assertions
  1. cpe:2.3:o:cisco:ip_phone_8851_firmware:11.0\(5\)sr1:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    1 · node/0 · match 2
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    07844dc0-2e7a-4540-897d-c4e2b440c4eb
  2. cpe:2.3:o:cisco:ip_phone_8851_firmware:11.0\(1\):*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    1 · node/0 · match 1
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    bb5548d1-7e70-4e75-b0fc-fc390b858612
  3. cpe:2.3:o:cisco:ip_phone_8851_firmware:10.3\(1\)es14:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    1 · node/0 · match 0
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    5800ebc5-4c54-46e9-b742-a49ee6d57a32
NVD CPE · HARDWAREciscoip_phone_8861Environmental constraint · 1 assertions
Version not applicableCanonical identity product-7def30f9cabf30dca44e0cc5f43657f734bf3535ebfe530b47e807709c5643cfLinked exact
Scope constrained
Inspect raw assertion
  1. cpe:2.3:h:cisco:ip_phone_8861:-:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Environmental constraint
    Configuration
    5 · node/1 · match 0
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    090ee553-01d5-45f0-87a4-e1167f46eb77
NVD CPE · OPERATING SYSTEMciscoip_phone_8861_firmwareVulnerable target · 3 assertions
Version 10.3(1)es14; Version 11.0(1); Version 11.0(5)sr1Canonical identity product-c31f2035a3f5fa11dcb1911bf77202293ce716c315e892ac7bf1a400cbe35797Linked exact
Scope supported
Inspect raw assertions
  1. cpe:2.3:o:cisco:ip_phone_8861_firmware:11.0\(1\):*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    5 · node/0 · match 1
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    f5e2cdc1-4031-4f88-94c2-4aa7ac112d87
  2. cpe:2.3:o:cisco:ip_phone_8861_firmware:11.0\(5\)sr1:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    5 · node/0 · match 2
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    228ada90-87b0-4bbf-a7cb-abdc2509e5a7
  3. cpe:2.3:o:cisco:ip_phone_8861_firmware:10.3\(1\)es14:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    5 · node/0 · match 0
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    d1350005-a1e5-4794-b853-9db3494c3b78

Affected-product evidence

Accepted scope and product mapping

13 canonical links · 1 source-reported links

Mapping establishedEvidence supported

vendor-0774b265c0e837e737aaf99ed0f2450c048e61f34267ca59d8623878b839334e · product-1fdf650c2a323d9c04c19edf1f15ef4b8ce264411264a77973eb5b42248103fe

Source class
Nvd cpe vulnerable target
Assertions
3
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
10390392-f780-401d-b771-22c45c5b2d7527bf34a7-d520-4473-8043-3120e9535fb5eeeb39b2-3e01-4e3d-9429-32c20e71e883
Mapping establishedEvidence supported

vendor-0774b265c0e837e737aaf99ed0f2450c048e61f34267ca59d8623878b839334e · product-33ba62de716df894763e95d4d96f230c752266159800cc8c2a9a9b8b529c8852

Source class
Nvd cpe vulnerable target
Assertions
3
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
94772116-c4ba-4643-92b5-0998b43a2c9fa5a78a34-d5a4-4fec-af6d-3c499fca777bf3a7bf70-0967-45e4-9e39-19538f3b32cc
Mapping establishedEvidence supported

vendor-0774b265c0e837e737aaf99ed0f2450c048e61f34267ca59d8623878b839334e · product-411b33c5e276ef0c39aa596afe050d64dabb2baa11d52bfeeedefcf7dcc29913

Source class
Nvd cpe vulnerable target
Assertions
1
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
731b4cba-a1cf-4fd3-9bd6-cc7f55641cd7
Mapping establishedEvidence supported

vendor-0774b265c0e837e737aaf99ed0f2450c048e61f34267ca59d8623878b839334e · product-42c15c017be5a6ff16425a95f494b03419e1f748f3c7a760e307c317447cf4ff

Source class
Nvd cpe vulnerable target
Assertions
3
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
275402f3-8c26-4ce5-bbb4-be0e3bf9119732cefc8b-4468-44ed-8922-2c83b9cc76cfc5d0bcef-30af-415a-be65-7f006d798cf6
Mapping establishedEvidence supported

vendor-0774b265c0e837e737aaf99ed0f2450c048e61f34267ca59d8623878b839334e · product-61ff42227fd1af35ac0340b3c9128940af6d86d72d6293e3393aa857f9f4489d

Source class
Nvd cpe vulnerable target
Assertions
1
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
a664032d-3791-48b7-b119-b9f74efb0f77
Mapping establishedEvidence supported

vendor-0774b265c0e837e737aaf99ed0f2450c048e61f34267ca59d8623878b839334e · product-7c58e83d55b59794b5baabeb5063f32e68fc1530138f70ceb5e09e285149eb68

Source class
Nvd cpe vulnerable target
Assertions
3
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
257f77cf-ffdc-4e12-8acb-b0ddde614d0f4ef019d3-108d-4cb7-9249-1b62356d14e48dc01fb4-f495-449e-a53d-f882ae7daeff
Mapping establishedEvidence supported

vendor-0774b265c0e837e737aaf99ed0f2450c048e61f34267ca59d8623878b839334e · product-837b408c7aa1479d0484790e5e6abe022af11c7c443080843578e88396eef0f2

Source class
Nvd cpe vulnerable target
Assertions
3
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
8a6aba9d-4e88-41b2-83df-04cb22a4a71fe9318a81-8aad-4349-a40e-d5dda3254f15ebb0cdfb-1ced-45ac-bb9d-6e7b0e82cdd1
Mapping establishedEvidence supported

vendor-0774b265c0e837e737aaf99ed0f2450c048e61f34267ca59d8623878b839334e · product-8d6a2a63a0314eb6c4115bf298817704e04c9db4b4387d8c3906cc89cca85a51

Source class
Nvd cpe vulnerable target
Assertions
3
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
14f09c08-a292-4238-a151-2dc1710bef9aa0226020-a678-49dc-a6a0-616585b089c3df4ad7b2-741a-4461-a2b2-bb8b96389414
Mapping establishedEvidence supported

vendor-0774b265c0e837e737aaf99ed0f2450c048e61f34267ca59d8623878b839334e · product-b14957199e4d341bce8e57b17bce50f294753fb58288cbe9cdd2c9d1e03c116c

Source class
Nvd cpe vulnerable target
Assertions
3
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
099072ff-9697-49cc-882a-63801d6959146c067be5-a155-4073-ac2d-b18f35158aced839368e-f13a-4ec6-9dbd-17c78617224c
Mapping establishedEvidence supported

vendor-0774b265c0e837e737aaf99ed0f2450c048e61f34267ca59d8623878b839334e · product-c31f2035a3f5fa11dcb1911bf77202293ce716c315e892ac7bf1a400cbe35797

Source class
Nvd cpe vulnerable target
Assertions
3
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
4aecbd91-a249-4155-8887-48c159e3ad825971489d-eb59-4f51-8016-75fc288ef261a508798d-b487-4c54-b059-ff065598dc23
Mapping establishedEvidence supported

vendor-0774b265c0e837e737aaf99ed0f2450c048e61f34267ca59d8623878b839334e · product-cf6c91411318ebba7fc0b59bdb1c39db79dba82ec543fe6db9c28f73dc96bccf

Source class
Nvd cpe vulnerable target
Assertions
3
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
0b4324a8-1c1d-4b05-934b-6895806482bf7388bf5a-8cec-4b67-bbb4-5dc038a6d2c4c4e122d9-72b7-4bb9-a271-0d23d5080e30
Mapping establishedEvidence supported

vendor-0774b265c0e837e737aaf99ed0f2450c048e61f34267ca59d8623878b839334e · product-d47a44eb1ce067a1ef304472bf6e705298521f0e8d78e702c9ae41f524eaf3a9

Source class
Nvd cpe vulnerable target
Assertions
1
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
7385cb2e-1226-4750-8277-1538798539f7
Mapping establishedEvidence supported

vendor-0774b265c0e837e737aaf99ed0f2450c048e61f34267ca59d8623878b839334e · product-e2c44e24b591b7f8e13b802c05b8bc4eacdb24f46ac11fa4f86f7d18e16ee25b

Source class
Nvd cpe vulnerable target
Assertions
1
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
12a4d748-ce56-4da9-9fe7-762d4f00a289
Source-reported scopeSource-reported scope

Canonical linkage remains open; the cited source assertion is retained below.

Vendor specified only by source · Product specified only by source

Source class
Direct cve affected
Assertions
1
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
9bf79161-bd63-454f-9351-08d879333c96

Assessments

CVSS by origin

9.8
NVDCVSS 3.1 · role Primary · priority eligiblevalid_matchCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
10.0
NVDCVSS 2.0 · role Primary · priority eligiblevalid_matchAV:N/AC:L/Au:N/C:C/I:C/A:C
9.8
psirt@cisco.comCVSS 3.0 · role Secondary · priority eligiblevalid_matchCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
9.8
ciscoCVSS 3.0 · role unknown · display onlyDirect record assessment retained outside normalized eligibilityCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Direct CVE/CNA normalized decisions

9.8Priority eligible

cisco

CVSS 3.0 · Primary · Original assertion · rank 1

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Validation
Valid match
Recomputed
9.8
Decision reason
Evidence supported
Policy
casca-direct-cvss-eligibility-v1

Assessments are retained side by side under closed precedence. Cascade never averages CVSS.

Evidence boundaries

  • KEV membership is authoritative for the catalog, not proof of exposure in any environment.
  • EPSS is a dated model probability and not an individual-environment prediction.
  • Affected or fixed status applies only to the exact cited product and version scope; remaining scope stays source-scoped.
  • NVD-carried upstream facts remain derivative; independent corroboration requires a separately authored source.
  • Only NVD metrics validated under the generation-bound calculator are Public Priority eligible; direct CVE record metrics remain display-only.
  • NVD CVSS source eligibility is closed: NVD-authored, exact record-source, or registered same-CVE container origin; unmapped sources remain display-only.
  • Core replay supports the active and immediately prior generation; retrospective valid-at replay is deferred.
  • OSV aggregation and OSV-converted NVD material are not independent corroboration.
  • Red Hat facts are vendor assertions for the exact supplied products.
  • Nonmembership and not-yet-observed states are not proof of safety.