The Serviceability servlet on Cisco 9900 IP phones does not properly restrict paths, which allows remote attackers to read arbitrary files by specifying a pathname in a file request, aka Bug ID CSCuh52810.
http://tools.cisco.com/security/center/content/CiscoSecurityNotice/CVE-2013-3426