The su utility on Cisco Unified IP Phones 7900 devices (aka TNP phones) with software before 9.0.3 allows local users to gain privileges via unspecified vectors, aka Bug ID CSCtf07426.
Conclusion & alert: CVE-2011-1602 is rated Low Risk (32.7/100): CVSS Medium severity, with low exploitation likelihood (EPSS 0.26%). Mandatory action: Monitor for updates and reassess as exploit intelligence or EPSS changes.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).
| # | Date | Old EPSS score | New EPSS score | Delta (New - Old) |
|---|---|---|---|---|
| 1 | 2026-06-15 | 0.06% | 0.26% | +0.20% |
| 2 | 2025-03-17 | 0.04% | 0.06% | +0.02% |
| 3 | 2023-03-07 | — | 0.04% | — |
Full EPSS history (4 records total)
CVSS metrics for this CVE.
| Base score | Version | Severity | Vector | Exploitability | Impact | Score source |
|---|---|---|---|---|---|---|
| 6.6 | 2.0 | MEDIUM |
|
2.7 | 10.0 | [email protected] |
| Vendor | Product | Version | Raw CPE |
|---|---|---|---|
| cisco | unified_ip_phone_7906 | — | cpe:2.3:h:cisco:unified_ip_phone_7906:*:*:*:*:*:*:*:* |
| cisco | unified_ip_phone_7911g | — | cpe:2.3:h:cisco:unified_ip_phone_7911g:*:*:*:*:*:*:*:* |
| cisco | unified_ip_phone_7931g | — | cpe:2.3:h:cisco:unified_ip_phone_7931g:*:*:*:*:*:*:*:* |
| cisco | unified_ip_phone_7941g | — | cpe:2.3:h:cisco:unified_ip_phone_7941g:*:*:*:*:*:*:*:* |
| cisco | unified_ip_phone_7941g-ge | — | cpe:2.3:h:cisco:unified_ip_phone_7941g-ge:*:*:*:*:*:*:*:* |
| cisco | unified_ip_phone_7942g | — | cpe:2.3:h:cisco:unified_ip_phone_7942g:*:*:*:*:*:*:*:* |
| cisco | unified_ip_phone_7945g | — | cpe:2.3:h:cisco:unified_ip_phone_7945g:*:*:*:*:*:*:*:* |
| cisco | unified_ip_phone_7961g | — | cpe:2.3:h:cisco:unified_ip_phone_7961g:*:*:*:*:*:*:*:* |
| cisco | unified_ip_phone_7961g-ge | — | cpe:2.3:h:cisco:unified_ip_phone_7961g-ge:*:*:*:*:*:*:*:* |
| cisco | unified_ip_phone_7962g | — | cpe:2.3:h:cisco:unified_ip_phone_7962g:*:*:*:*:*:*:*:* |
| cisco | unified_ip_phone_7965g | — | cpe:2.3:h:cisco:unified_ip_phone_7965g:*:*:*:*:*:*:*:* |
| cisco | unified_ip_phone_7970g | — | cpe:2.3:h:cisco:unified_ip_phone_7970g:*:*:*:*:*:*:*:* |
| cisco | unified_ip_phone_7971g-ge | — | cpe:2.3:h:cisco:unified_ip_phone_7971g-ge:*:*:*:*:*:*:*:* |
| cisco | unified_ip_phone_7975g | — | cpe:2.3:h:cisco:unified_ip_phone_7975g:*:*:*:*:*:*:*:* |
| cisco | skinny_client_control_protocol_software | <= 9.0\(2\) | cpe:2.3:o:cisco:skinny_client_control_protocol_software:*:sr2:*:*:*:*:*:* |
| cisco | skinny_client_control_protocol_software | 1.0\(1\) | cpe:2.3:o:cisco:skinny_client_control_protocol_software:1.0\(1\):*:*:*:*:*:*:* |
| cisco | skinny_client_control_protocol_software | 1.0\(2\) | cpe:2.3:o:cisco:skinny_client_control_protocol_software:1.0\(2\):*:*:*:*:*:*:* |
| cisco | skinny_client_control_protocol_software | 1.0\(2\) | cpe:2.3:o:cisco:skinny_client_control_protocol_software:1.0\(2\):sr1:*:*:*:*:*:* |
| cisco | skinny_client_control_protocol_software | 1.0\(3\) | cpe:2.3:o:cisco:skinny_client_control_protocol_software:1.0\(3\):*:*:*:*:*:*:* |
| cisco | skinny_client_control_protocol_software | 1.0\(4\) | cpe:2.3:o:cisco:skinny_client_control_protocol_software:1.0\(4\):*:*:*:*:*:*:* |
| cisco | skinny_client_control_protocol_software | 1.0\(5\) | cpe:2.3:o:cisco:skinny_client_control_protocol_software:1.0\(5\):*:*:*:*:*:*:* |
| cisco | skinny_client_control_protocol_software | 1.0\(9\) | cpe:2.3:o:cisco:skinny_client_control_protocol_software:1.0\(9\):*:*:*:*:*:*:* |
| cisco | skinny_client_control_protocol_software | 1.1\(1\) | cpe:2.3:o:cisco:skinny_client_control_protocol_software:1.1\(1\):*:*:*:*:*:*:* |
| cisco | skinny_client_control_protocol_software | 1.2\(1\) | cpe:2.3:o:cisco:skinny_client_control_protocol_software:1.2\(1\):*:*:*:*:*:*:* |
| cisco | skinny_client_control_protocol_software | 1.3\(1\) | cpe:2.3:o:cisco:skinny_client_control_protocol_software:1.3\(1\):*:*:*:*:*:*:* |
| cisco | skinny_client_control_protocol_software | 1.3\(2\) | cpe:2.3:o:cisco:skinny_client_control_protocol_software:1.3\(2\):*:*:*:*:*:*:* |
| cisco | skinny_client_control_protocol_software | 1.3\(3\) | cpe:2.3:o:cisco:skinny_client_control_protocol_software:1.3\(3\):*:*:*:*:*:*:* |
| cisco | skinny_client_control_protocol_software | 1.3\(4\) | cpe:2.3:o:cisco:skinny_client_control_protocol_software:1.3\(4\):*:*:*:*:*:*:* |
| cisco | skinny_client_control_protocol_software | 1.3\(4\) | cpe:2.3:o:cisco:skinny_client_control_protocol_software:1.3\(4\):sr1:*:*:*:*:*:* |
| cisco | skinny_client_control_protocol_software | 1.4\(1\) | cpe:2.3:o:cisco:skinny_client_control_protocol_software:1.4\(1\):*:*:*:*:*:*:* |
| cisco | skinny_client_control_protocol_software | 1.4\(2\) | cpe:2.3:o:cisco:skinny_client_control_protocol_software:1.4\(2\):*:*:*:*:*:*:* |
| cisco | skinny_client_control_protocol_software | 2.0\(0\) | cpe:2.3:o:cisco:skinny_client_control_protocol_software:2.0\(0\):*:*:*:*:*:*:* |
| cisco | skinny_client_control_protocol_software | 2.0\(1\) | cpe:2.3:o:cisco:skinny_client_control_protocol_software:2.0\(1\):*:*:*:*:*:*:* |
| cisco | skinny_client_control_protocol_software | 3.0 | cpe:2.3:o:cisco:skinny_client_control_protocol_software:3.0:*:*:*:*:*:*:* |
| cisco | skinny_client_control_protocol_software | 3.0\(0\) | cpe:2.3:o:cisco:skinny_client_control_protocol_software:3.0\(0\):*:*:*:*:*:*:* |
| cisco | skinny_client_control_protocol_software | 3.0\(1\) | cpe:2.3:o:cisco:skinny_client_control_protocol_software:3.0\(1\):*:*:*:*:*:*:* |
| cisco | skinny_client_control_protocol_software | 3.0\(2\) | cpe:2.3:o:cisco:skinny_client_control_protocol_software:3.0\(2\):*:*:*:*:*:*:* |
| cisco | skinny_client_control_protocol_software | 3.1 | cpe:2.3:o:cisco:skinny_client_control_protocol_software:3.1:*:*:*:*:*:*:* |
| cisco | skinny_client_control_protocol_software | 3.1\(1\) | cpe:2.3:o:cisco:skinny_client_control_protocol_software:3.1\(1\):*:*:*:*:*:*:* |
| cisco | skinny_client_control_protocol_software | 3.1\(2\) | cpe:2.3:o:cisco:skinny_client_control_protocol_software:3.1\(2\):*:*:*:*:*:*:* |
| cisco | skinny_client_control_protocol_software | 3.1\(3\) | cpe:2.3:o:cisco:skinny_client_control_protocol_software:3.1\(3\):*:*:*:*:*:*:* |
| cisco | skinny_client_control_protocol_software | 3.1\(4\) | cpe:2.3:o:cisco:skinny_client_control_protocol_software:3.1\(4\):*:*:*:*:*:*:* |
| cisco | skinny_client_control_protocol_software | 3.1\(6\) | cpe:2.3:o:cisco:skinny_client_control_protocol_software:3.1\(6\):*:*:*:*:*:*:* |
| cisco | skinny_client_control_protocol_software | 3.1\(10\) | cpe:2.3:o:cisco:skinny_client_control_protocol_software:3.1\(10\):*:*:*:*:*:*:* |
| cisco | skinny_client_control_protocol_software | 3.1\(11\) | cpe:2.3:o:cisco:skinny_client_control_protocol_software:3.1\(11\):*:*:*:*:*:*:* |
| cisco | skinny_client_control_protocol_software | 3.2 | cpe:2.3:o:cisco:skinny_client_control_protocol_software:3.2:*:*:*:*:*:*:* |
| cisco | skinny_client_control_protocol_software | 3.2\(1\) | cpe:2.3:o:cisco:skinny_client_control_protocol_software:3.2\(1\):*:*:*:*:*:*:* |
| cisco | skinny_client_control_protocol_software | 3.2\(2\) | cpe:2.3:o:cisco:skinny_client_control_protocol_software:3.2\(2\):*:*:*:*:*:*:* |
| cisco | skinny_client_control_protocol_software | 3.2\(3\) | cpe:2.3:o:cisco:skinny_client_control_protocol_software:3.2\(3\):*:*:*:*:*:*:* |
| cisco | skinny_client_control_protocol_software | 3.2\(4\) | cpe:2.3:o:cisco:skinny_client_control_protocol_software:3.2\(4\):*:*:*:*:*:*:* |
| cisco | skinny_client_control_protocol_software | 3.2\(5\) | cpe:2.3:o:cisco:skinny_client_control_protocol_software:3.2\(5\):*:*:*:*:*:*:* |
| cisco | skinny_client_control_protocol_software | 3.2\(6\) | cpe:2.3:o:cisco:skinny_client_control_protocol_software:3.2\(6\):*:*:*:*:*:*:* |
| cisco | skinny_client_control_protocol_software | 3.2\(6a\) | cpe:2.3:o:cisco:skinny_client_control_protocol_software:3.2\(6a\):*:*:*:*:*:*:* |
| cisco | skinny_client_control_protocol_software | 3.2\(7\) | cpe:2.3:o:cisco:skinny_client_control_protocol_software:3.2\(7\):*:*:*:*:*:*:* |
| cisco | skinny_client_control_protocol_software | 3.2\(8\) | cpe:2.3:o:cisco:skinny_client_control_protocol_software:3.2\(8\):*:*:*:*:*:*:* |
| cisco | skinny_client_control_protocol_software | 3.2\(9\) | cpe:2.3:o:cisco:skinny_client_control_protocol_software:3.2\(9\):*:*:*:*:*:*:* |
| cisco | skinny_client_control_protocol_software | 3.2\(10\) | cpe:2.3:o:cisco:skinny_client_control_protocol_software:3.2\(10\):*:*:*:*:*:*:* |
| cisco | skinny_client_control_protocol_software | 3.2\(11\) | cpe:2.3:o:cisco:skinny_client_control_protocol_software:3.2\(11\):*:*:*:*:*:*:* |
| cisco | skinny_client_control_protocol_software | 3.2\(12\) | cpe:2.3:o:cisco:skinny_client_control_protocol_software:3.2\(12\):*:*:*:*:*:*:* |
| cisco | skinny_client_control_protocol_software | 3.2\(13\) | cpe:2.3:o:cisco:skinny_client_control_protocol_software:3.2\(13\):*:*:*:*:*:*:* |
| cisco | skinny_client_control_protocol_software | 3.2\(14\) | cpe:2.3:o:cisco:skinny_client_control_protocol_software:3.2\(14\):*:*:*:*:*:*:* |
| cisco | skinny_client_control_protocol_software | 3.2\(15\) | cpe:2.3:o:cisco:skinny_client_control_protocol_software:3.2\(15\):*:*:*:*:*:*:* |
| cisco | skinny_client_control_protocol_software | 3.3\(2\) | cpe:2.3:o:cisco:skinny_client_control_protocol_software:3.3\(2\):*:*:*:*:*:*:* |
| cisco | skinny_client_control_protocol_software | 3.3\(3\) | cpe:2.3:o:cisco:skinny_client_control_protocol_software:3.3\(3\):*:*:*:*:*:*:* |
| cisco | skinny_client_control_protocol_software | 3.3\(4\) | cpe:2.3:o:cisco:skinny_client_control_protocol_software:3.3\(4\):*:*:*:*:*:*:* |
| cisco | skinny_client_control_protocol_software | 3.3\(5\) | cpe:2.3:o:cisco:skinny_client_control_protocol_software:3.3\(5\):*:*:*:*:*:*:* |
| cisco | skinny_client_control_protocol_software | 3.3\(6\) | cpe:2.3:o:cisco:skinny_client_control_protocol_software:3.3\(6\):*:*:*:*:*:*:* |
| cisco | skinny_client_control_protocol_software | 3.3\(7\) | cpe:2.3:o:cisco:skinny_client_control_protocol_software:3.3\(7\):*:*:*:*:*:*:* |
| cisco | skinny_client_control_protocol_software | 3.3\(8\) | cpe:2.3:o:cisco:skinny_client_control_protocol_software:3.3\(8\):*:*:*:*:*:*:* |
| cisco | skinny_client_control_protocol_software | 3.3\(9\) | cpe:2.3:o:cisco:skinny_client_control_protocol_software:3.3\(9\):*:*:*:*:*:*:* |
| cisco | skinny_client_control_protocol_software | 3.3\(10\) | cpe:2.3:o:cisco:skinny_client_control_protocol_software:3.3\(10\):*:*:*:*:*:*:* |
| cisco | skinny_client_control_protocol_software | 3.3\(11\) | cpe:2.3:o:cisco:skinny_client_control_protocol_software:3.3\(11\):*:*:*:*:*:*:* |
| cisco | skinny_client_control_protocol_software | 3.3\(12\) | cpe:2.3:o:cisco:skinny_client_control_protocol_software:3.3\(12\):*:*:*:*:*:*:* |
| cisco | skinny_client_control_protocol_software | 3.3\(13\) | cpe:2.3:o:cisco:skinny_client_control_protocol_software:3.3\(13\):*:*:*:*:*:*:* |
| cisco | skinny_client_control_protocol_software | 3.3\(14\) | cpe:2.3:o:cisco:skinny_client_control_protocol_software:3.3\(14\):*:*:*:*:*:*:* |
| cisco | skinny_client_control_protocol_software | 3.3\(15\) | cpe:2.3:o:cisco:skinny_client_control_protocol_software:3.3\(15\):*:*:*:*:*:*:* |
| cisco | skinny_client_control_protocol_software | 3.3\(16\) | cpe:2.3:o:cisco:skinny_client_control_protocol_software:3.3\(16\):*:*:*:*:*:*:* |
| cisco | skinny_client_control_protocol_software | 3.3\(20\) | cpe:2.3:o:cisco:skinny_client_control_protocol_software:3.3\(20\):*:*:*:*:*:*:* |
| cisco | skinny_client_control_protocol_software | 4.0\(0\) | cpe:2.3:o:cisco:skinny_client_control_protocol_software:4.0\(0\):*:*:*:*:*:*:* |
| cisco | skinny_client_control_protocol_software | 4.1\(2\) | cpe:2.3:o:cisco:skinny_client_control_protocol_software:4.1\(2\):*:*:*:*:*:*:* |