CVE-2023-20018
published 2023-01-20CVE-2023-20018: A vulnerability in the web-based management interface of Cisco IP Phone 7800 and 8800 Series Phones could allow an unauthenticated, remote attacker to bypass…
PriorityP339medium6.5CVSS 3.1
AVNACLPRNUINSUCLILAN
EPSS
0.61%
45.7th percentile
A vulnerability in the web-based management interface of Cisco IP Phone 7800 and 8800 Series Phones could allow an unauthenticated, remote attacker to bypass authentication on an affected device.
This vulnerability is due to insufficient validation of user-supplied input. An attacker could exploit this vulnerability by sending a crafted request to the web-based management interface. A successful exploit could allow the attacker to access certain parts of the web interface that would normally require authentication.
Affected
99 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | cisco_session_initiation_protocol_software | — | — |
| cisco | cisco_session_initiation_protocol_software | — | — |
| cisco | cisco_session_initiation_protocol_software | — | — |
| cisco | cisco_session_initiation_protocol_software | — | — |
| cisco | cisco_session_initiation_protocol_software | — | — |
| cisco | cisco_session_initiation_protocol_software | — | — |
| cisco | cisco_session_initiation_protocol_software | — | — |
| cisco | cisco_session_initiation_protocol_software | — | — |
| cisco | cisco_session_initiation_protocol_software | — | — |
| cisco | cisco_session_initiation_protocol_software | — | — |
| cisco | cisco_session_initiation_protocol_software | — | — |
| cisco | cisco_session_initiation_protocol_software | — | — |
| cisco | cisco_session_initiation_protocol_software | — | — |
| cisco | cisco_session_initiation_protocol_software | — | — |
| cisco | cisco_session_initiation_protocol_software | — | — |
| cisco | cisco_session_initiation_protocol_software | — | — |
| cisco | cisco_session_initiation_protocol_software | — | — |
| cisco | cisco_session_initiation_protocol_software | — | — |
| cisco | cisco_session_initiation_protocol_software | — | — |
| cisco | cisco_session_initiation_protocol_software | — | — |
| cisco | cisco_session_initiation_protocol_software | — | — |
| cisco | cisco_session_initiation_protocol_software | — | — |
| cisco | cisco_session_initiation_protocol_software | — | — |
| cisco | cisco_session_initiation_protocol_software | — | — |
| cisco | cisco_session_initiation_protocol_software | — | — |
CVSS provenance
nvdv3.16.5MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
vendor_cisco8.6HIGH
vendor_redhat5.5LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
kernel: vfio: Fix NULL pointer dereference caused by uninitialized group->iommufd
vendor_redhat·2025-12-30·CVSS 5.5
CVE-2023-54174 [LOW] CWE-824 kernel: vfio: Fix NULL pointer dereference caused by uninitialized group->iommufd
kernel: vfio: Fix NULL pointer dereference caused by uninitialized group->iommufd
In the Linux kernel, the following vulnerability has been resolved:
vfio: Fix NULL pointer dereference caused by uninitialized group->iommufd
group->iommufd is not initialized for the iommufd_ctx_put()
[20018.331541] BUG: kernel NULL pointer dereference, address: 0000000000000000
[20018.377508] RIP: 0010:iommufd_ctx_put+0x5/0x10 [iommufd]
...
[20018.476483] Call Trace:
[20018.479214]
[20018.481555] vfio_group_fops_unl_ioctl+0x506/0x690 [vfio]
[20018.487586] __x64_sys_ioctl+0x6a/0xb0
[20018.491773] ? trace_hardirqs_on+0xc5/0xe0
[20018.496347] do_syscall_64+0x67/0x90
[20018.500340] entry_SYSCALL_64_after_hwframe+0x4b/0xb5
A NULL pointer dereference was found in the VFIO subsystem. When a VFIO group operation
Cisco
Cisco IP Phone 7800 and 8800 Series Web Management Interface Authentication Bypass Vulnerability
vendor_cisco·2023-01-11·CVSS 8.6
CVE-2023-20018 [HIGH] CWE-288 Cisco IP Phone 7800 and 8800 Series Web Management Interface Authentication Bypass Vulnerability
Cisco IP Phone 7800 and 8800 Series Web Management Interface Authentication Bypass Vulnerability
A vulnerability in the web-based management interface of Cisco IP Phone 7800 and 8800 Series Phones could allow an unauthenticated, remote attacker to bypass authentication on an affected device.
This vulnerability is due to insufficient validation of user-supplied input. An attacker could exploit this vulnerability by sending a crafted request to the web-based management interface. A successful exploit could allow the attacker to access certain parts of the web interface that would normally require authentication.
Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability.
This advisory is available at the following link:http
Cisco
Cisco IP Phone 7800 and 8800 Series Web Management Interface Authentication Bypass Vulnerability
vendor_cisco·CVSS 3.1
CVE-2023-20018 Cisco IP Phone 7800 and 8800 Series Web Management Interface Authentication Bypass Vulnerability
CVE-2023-20018: Cisco IP Phone 7800 and 8800 Series Web Management Interface Authentication Bypass Vulnerability
A vulnerability in the web-based management interface of Cisco IP Phone 7800 and 8800 Series Phones could allow an unauthenticated, remote attacker to bypass authentication on an affected device. This vulnerability is due to insufficient validation of user-supplied input. An attacker could exploit this vulnerability by sending a crafted request to the web-based management interface. A successful exploit could allow the attacker to access certain parts of the web interface that would normally require authentication. Cisco has released software updates that address this vulnerability. There are no
CVSS: 3.1
CWE: CWE-288, CWE-288
Bug IDs: CSCwc37223, CSCwc37234
OSV
vfio: Fix NULL pointer dereference caused by uninitialized group->iommufd
osv·2025-12-30
CVE-2023-54174 vfio: Fix NULL pointer dereference caused by uninitialized group->iommufd
vfio: Fix NULL pointer dereference caused by uninitialized group->iommufd
In the Linux kernel, the following vulnerability has been resolved:
vfio: Fix NULL pointer dereference caused by uninitialized group->iommufd
group->iommufd is not initialized for the iommufd_ctx_put()
[20018.331541] BUG: kernel NULL pointer dereference, address: 0000000000000000
[20018.377508] RIP: 0010:iommufd_ctx_put+0x5/0x10 [iommufd]
...
[20018.476483] Call Trace:
[20018.479214]
[20018.481555] vfio_group_fops_unl_ioctl+0x506/0x690 [vfio]
[20018.487586] __x64_sys_ioctl+0x6a/0xb0
[20018.491773] ? trace_hardirqs_on+0xc5/0xe0
[20018.496347] do_syscall_64+0x67/0x90
[20018.500340] entry_SYSCALL_64_after_hwframe+0x4b/0xb5
GHSA
GHSA-jc6w-v2gh-gqx3: A vulnerability in the web-based management interface of Cisco IP Phone 7800 and 8800 Series Phones could allow an unauthenticated, remote attacker to
ghsa_unreviewed·2023-01-20
CVE-2023-20018 [MEDIUM] CWE-288 GHSA-jc6w-v2gh-gqx3: A vulnerability in the web-based management interface of Cisco IP Phone 7800 and 8800 Series Phones could allow an unauthenticated, remote attacker to
A vulnerability in the web-based management interface of Cisco IP Phone 7800 and 8800 Series Phones could allow an unauthenticated, remote attacker to bypass authentication on an affected device. This vulnerability is due to insufficient validation of user-supplied input. An attacker could exploit this vulnerability by sending a crafted request to the web-based management interface. A successful exploit could allow the attacker to access certain parts of the web interface that would normally require authentication.
No detection rules found.
No public exploits indexed.
2023-01-20
Published