CVE-2023-20018

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
20/01/2023
Last modified:
25/01/2024

Description

A vulnerability in the web-based management interface of Cisco IP Phone 7800 and 8800 Series Phones could allow an unauthenticated, remote attacker to bypass authentication on an affected device.<br /> <br /> This vulnerability is due to insufficient validation of user-supplied input. An attacker could exploit this vulnerability by sending a crafted request to the web-based management interface. A successful exploit could allow the attacker to access certain parts of the web interface that would normally require authentication.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:cisco:ip_phone_7800_firmware:*:*:*:*:*:*:*:* 14.1\(1\)sr2 (excluding)
cpe:2.3:h:cisco:ip_phone_7800:-:*:*:*:*:*:*:*
cpe:2.3:o:cisco:ip_phone_7811_firmware:*:*:*:*:*:*:*:* 14.1\(1\)sr2 (excluding)
cpe:2.3:h:cisco:ip_phone_7811:-:*:*:*:*:*:*:*
cpe:2.3:o:cisco:ip_phone_7821_firmware:*:*:*:*:*:*:*:* 14.1\(1\)sr2 (excluding)
cpe:2.3:h:cisco:ip_phone_7821:-:*:*:*:*:*:*:*
cpe:2.3:o:cisco:ip_phone_7832_firmware:*:*:*:*:*:*:*:* 14.1\(1\)sr2 (excluding)
cpe:2.3:h:cisco:ip_phone_7832:-:*:*:*:*:*:*:*
cpe:2.3:o:cisco:ip_phone_7841_firmware:*:*:*:*:*:*:*:* 14.1\(1\)sr2 (excluding)
cpe:2.3:h:cisco:ip_phone_7841:-:*:*:*:*:*:*:*
cpe:2.3:o:cisco:ip_phone_7861_firmware:*:*:*:*:*:*:*:* 14.1\(1\)sr2 (excluding)
cpe:2.3:h:cisco:ip_phone_7861:-:*:*:*:*:*:*:*
cpe:2.3:o:cisco:ip_phone_8800_firmware:*:*:*:*:*:*:*:* 14.1\(1\)sr2 (excluding)
cpe:2.3:h:cisco:ip_phone_8800:-:*:*:*:*:*:*:*
cpe:2.3:o:cisco:ip_phone_8811_firmware:*:*:*:*:*:*:*:* 14.1\(1\)sr2 (excluding)