Cisco Ip Phone 8821-Ex Firmware vulnerabilities
6 known vulnerabilities affecting cisco/ip_phone_8821-ex_firmware.
Total CVEs
6
CISA KEV
1
actively exploited
Public exploits
1
Exploited in wild
1
Severity breakdown
CRITICAL2HIGH2MEDIUM2
Vulnerabilities
Page 1 of 1
CVE-2023-20018MEDIUMCVSS 6.5fixed in 14.1\(1\)sr22023-01-20
CVE-2023-20018 [HIGH] CWE-288 CVE-2023-20018: A vulnerability in the web-based management interface of Cisco IP Phone 7800 and 8800 Series Phones
A vulnerability in the web-based management interface of Cisco IP Phone 7800 and 8800 Series Phones could allow an unauthenticated, remote attacker to bypass authentication on an affected device.
This vulnerability is due to insufficient validation of user-supplied input. An attacker could exploit this vulnerability by sending a crafted request to the
nvd
CVE-2020-3161CRITICALCVSS 9.8KEVPoCv10.3\(1\)es14v11.0\(1\)+1 more2020-04-15
CVE-2020-3161 [CRITICAL] CWE-20 CVE-2020-3161: A vulnerability in the web server for Cisco IP Phones could allow an unauthenticated, remote attacke
A vulnerability in the web server for Cisco IP Phones could allow an unauthenticated, remote attacker to execute code with root privileges or cause a reload of an affected IP phone, resulting in a denial of service (DoS) condition. The vulnerability is due to a lack of proper input validation of HTTP requests. An attacker could exploit this vulnerabi
nvd
CVE-2019-1716CRITICALCVSS 9.8fixed in 11.0\(4\)sr32019-03-22
CVE-2019-1716 [HIGH] CWE-20 CVE-2019-1716: A vulnerability in the web-based management interface of Session Initiation Protocol (SIP) Software
A vulnerability in the web-based management interface of Session Initiation Protocol (SIP) Software for Cisco IP Phone 7800 Series and Cisco IP Phone 8800 Series could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition or execute arbitrary code. The vulnerability exists because the software improperly validates user-sup
nvd
CVE-2019-1764HIGHCVSS 8.8fixed in 11.0\(5\)2019-03-22
CVE-2019-1764 [HIGH] CWE-352 CVE-2019-1764: A vulnerability in the web-based management interface of Session Initiation Protocol (SIP) Software
A vulnerability in the web-based management interface of Session Initiation Protocol (SIP) Software for Cisco IP Phone 8800 Series could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack. The vulnerability is due to insufficient CSRF protections for the web-based management interface of an affected device. An
nvd
CVE-2019-1763HIGHCVSS 7.5fixed in 11.0\(5\)2019-03-22
CVE-2019-1763 [HIGH] CWE-284 CVE-2019-1763: A vulnerability in the web-based management interface of Session Initiation Protocol (SIP) Software
A vulnerability in the web-based management interface of Session Initiation Protocol (SIP) Software for Cisco IP Phone 8800 Series could allow an unauthenticated, remote attacker to bypass authorization, access critical services, and cause a denial of service (DoS) condition. The vulnerability exists because the software fails to sanitize URLs before it
nvd
CVE-2019-1765MEDIUMCVSS 6.5fixed in 11.0\(5\)2019-03-22
CVE-2019-1765 [HIGH] CWE-22 CVE-2019-1765: A vulnerability in the web-based management interface of Session Initiation Protocol (SIP) Software
A vulnerability in the web-based management interface of Session Initiation Protocol (SIP) Software for Cisco IP Phone 8800 Series could allow an authenticated, remote attacker to write arbitrary files to the filesystem. The vulnerability is due to insufficient input validation and file-level permissions. An attacker could exploit this vulnerability by up
nvd