Cisco Phoneos vulnerabilities
4 known vulnerabilities affecting cisco/cisco_phoneos.
Total CVEs
4
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH2MEDIUM2
Vulnerabilities
Page 1 of 1
CVE-2024-20376HIGHCVSS 7.5v1.0.1v2.1.1+2 more2024-05-01
CVE-2024-20376 [HIGH] CWE-787 CVE-2024-20376: A vulnerability in the web-based management interface of Cisco IP Phone firmware could allow an unau
A vulnerability in the web-based management interface of Cisco IP Phone firmware could allow an unauthenticated, remote attacker to cause an affected device to reload, resulting in a DoS condition.
This vulnerability is due to insufficient validation of user-supplied input. An attacker could exploit this vulnerability by sending a crafted request to t
cvelistv5nvd
CVE-2024-20378HIGHCVSS 7.5v1.0.1v2.1.1+2 more2024-05-01
CVE-2024-20378 [HIGH] CWE-305 CVE-2024-20378: A vulnerability in the web-based management interface of Cisco IP Phone firmware could allow an unau
A vulnerability in the web-based management interface of Cisco IP Phone firmware could allow an unauthenticated, remote attacker to retrieve sensitive information from an affected device.
This vulnerability is due to a lack of authentication for specific endpoints of the web-based management interface on an affected device. An attacker could exploit t
cvelistv5nvd
CVE-2024-20357MEDIUMCVSS 5.9v1.0.1v2.1.1+2 more2024-05-01
CVE-2024-20357 [MEDIUM] CWE-787 CVE-2024-20357: A vulnerability in the XML service of Cisco IP Phone firmware could allow an unauthenticated, remote
A vulnerability in the XML service of Cisco IP Phone firmware could allow an unauthenticated, remote attacker to initiate phone calls on an affected device.
This vulnerability exists because bounds-checking does not occur while parsing XML requests. An attacker could exploit this vulnerability by sending a crafted XML request to an affected device.
cvelistv5nvd
CVE-2023-20221MEDIUMCVSS 6.5v1.0.12023-08-16
CVE-2023-20221 [MEDIUM] CWE-352 CVE-2023-20221: A vulnerability in the web-based management interface of Cisco IP Phone 6800, 7800, and 8800 Series
A vulnerability in the web-based management interface of Cisco IP Phone 6800, 7800, and 8800 Series with Multiplatform Firmware could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack against a user of the web-based management interface of an affected system.
This vulnerability is due to insufficient CSRF
cvelistv5nvd