CVE-2024-20533
published 2024-11-06CVE-2024-20533: A vulnerability in the web UI of Cisco Desk Phone 9800 Series, Cisco IP Phone 6800, 7800, and 8800 Series, and Cisco Video Phone 8875 with Cisco Multiplatform…
PriorityP421medium4.8CVSS 3.1
AVNACLPRHUIRSCCLILAN
EPSS
0.27%
18.8th percentile
A vulnerability in the web UI of Cisco Desk Phone 9800 Series, Cisco IP Phone 6800, 7800, and 8800 Series, and Cisco Video Phone 8875 with Cisco Multiplatform Firmware could allow an authenticated, remote attacker to conduct stored cross-site scripting (XSS) attacks against users.
This vulnerability exists because the web UI of an affected device does not properly validate user-supplied input. An attacker could exploit this vulnerability by injecting malicious code into specific pages of the interface. A successful exploit could allow the attacker to execute arbitrary script code in the context of the affected interface or access sensitive, browser-based information.
Note: To exploit this vulnerability, Web Access must be enabled on the phone and the attacker must have Admin credentials on the device. Web Access is disabled by default.
Affected
69 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | 6800_7800_8800_and_9800_series_phones_with_multiplatform_firmware_stored | — | — |
| cisco | cisco_ip_phones_with_multiplatform_firmware | — | — |
| cisco | cisco_ip_phones_with_multiplatform_firmware | — | — |
| cisco | cisco_ip_phones_with_multiplatform_firmware | — | — |
| cisco | cisco_ip_phones_with_multiplatform_firmware | — | — |
| cisco | cisco_ip_phones_with_multiplatform_firmware | — | — |
| cisco | cisco_ip_phones_with_multiplatform_firmware | — | — |
| cisco | cisco_ip_phones_with_multiplatform_firmware | — | — |
| cisco | cisco_ip_phones_with_multiplatform_firmware | — | — |
| cisco | cisco_ip_phones_with_multiplatform_firmware | — | — |
| cisco | cisco_ip_phones_with_multiplatform_firmware | — | — |
| cisco | cisco_ip_phones_with_multiplatform_firmware | — | — |
| cisco | cisco_ip_phones_with_multiplatform_firmware | — | — |
| cisco | cisco_ip_phones_with_multiplatform_firmware | — | — |
| cisco | cisco_ip_phones_with_multiplatform_firmware | — | — |
| cisco | cisco_ip_phones_with_multiplatform_firmware | — | — |
| cisco | cisco_ip_phones_with_multiplatform_firmware | — | — |
| cisco | cisco_ip_phones_with_multiplatform_firmware | — | — |
| cisco | cisco_ip_phones_with_multiplatform_firmware | — | — |
| cisco | cisco_ip_phones_with_multiplatform_firmware | — | — |
| cisco | cisco_ip_phones_with_multiplatform_firmware | — | — |
| cisco | cisco_ip_phones_with_multiplatform_firmware | — | — |
| cisco | cisco_ip_phones_with_multiplatform_firmware | — | — |
| cisco | cisco_ip_phones_with_multiplatform_firmware | — | — |
| cisco | cisco_ip_phones_with_multiplatform_firmware | — | — |
CVSS provenance
nvdv3.14.8MEDIUMCVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N
vendor_cisco4.8MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Cisco
Cisco 6800, 7800, 8800, and 9800 Series Phones with Multiplatform Firmware Stored Cross-Site Scripting Vulnerabilities
vendor_cisco·2024-11-06·CVSS 4.8
CVE-2024-20533 [MEDIUM] CWE-79 Cisco 6800, 7800, 8800, and 9800 Series Phones with Multiplatform Firmware Stored Cross-Site Scripting Vulnerabilities
Cisco 6800, 7800, 8800, and 9800 Series Phones with Multiplatform Firmware Stored Cross-Site Scripting Vulnerabilities
Multiple vulnerabilities in the web UI of Cisco Desk Phone 9800 Series, Cisco IP Phone 6800, 7800, and 8800 Series, and Cisco Video Phone 8875 with Cisco Multiplatform Firmware could allow an authenticated, remote attacker to conduct stored cross-site scripting (XSS) attacks against users.
These vulnerabilities exist because the web UI of an affected device does not properly validate user-supplied input. An attacker could exploit these vulnerabilities by injecting malicious code into specific pages of the interface. A successful exploit could allow the attacker to execute arbitrary script code in the context of the affected interface or access sensitive, browser-based in
Cisco
Cisco 6800, 7800, 8800, and 9800 Series Phones with Multiplatform Firmware Stored Cross-Site Scripting Vulnerabilities
vendor_cisco·CVSS 3.1
CVE-2024-20533 Cisco 6800, 7800, 8800, and 9800 Series Phones with Multiplatform Firmware Stored Cross-Site Scripting Vulnerabilities
CVE-2024-20533: Cisco 6800, 7800, 8800, and 9800 Series Phones with Multiplatform Firmware Stored Cross-Site Scripting Vulnerabilities
Multiple vulnerabilities in the web UI of Cisco Desk Phone 9800 Series, Cisco IP Phone 6800, 7800, and 8800 Series, and Cisco Video Phone 8875 with Cisco Multiplatform Firmware could allow an authenticated, remote attacker to conduct stored cross-site scripting (XSS) attacks against users. These vulnerabilities exist because the web UI of an affected device does not properly validate user-supplied input. An attacker could exploit these vulnerabilities by injecting malicious code into specific pages of the interface. A successful exploit could allow the attacker to execute arbitrary script code in the context of the affected interface or access sensitive, br
GHSA
GHSA-rv5p-p324-cxv2: A vulnerability in the web UI of Cisco Desk Phone 9800 Series, Cisco IP Phone 6800, 7800, and 8800 Series, and Cisco Video Phone 8875 with Cisco Multi
ghsa_unreviewed·2024-11-06
CVE-2024-20533 [MEDIUM] CWE-79 GHSA-rv5p-p324-cxv2: A vulnerability in the web UI of Cisco Desk Phone 9800 Series, Cisco IP Phone 6800, 7800, and 8800 Series, and Cisco Video Phone 8875 with Cisco Multi
A vulnerability in the web UI of Cisco Desk Phone 9800 Series, Cisco IP Phone 6800, 7800, and 8800 Series, and Cisco Video Phone 8875 with Cisco Multiplatform Firmware could allow an authenticated, remote attacker to conduct stored cross-site scripting (XSS) attacks against users.
This vulnerability exists because the web UI of an affected device does not properly validate user-supplied input. An attacker could exploit this vulnerability by injecting malicious code into specific pages of the interface. A successful exploit could allow the attacker to execute arbitrary script code in the context of the affected interface or access sensitive, browser-based information.
Note: To exploit this vulnerability, Web Access must be enabled on the phone and the attacker must have Admin credentials o
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2024-11-06
Published