PT-2020-2964 · Cisco · Cisco Ip Phones Series 7800+1
Oguzhan Karaman
·
Published
2020-06-17
·
Updated
2021-08-06
·
CVE-2020-3360
CVSS v3.1
5.3
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Cisco IP Phones Series 7800 and Series 8800 (affected versions not specified)
Description
A vulnerability in the Web Access feature could allow an unauthenticated, remote attacker to view sensitive information on an affected device. This issue is due to improper access controls on the web-based management interface. An attacker could exploit this by sending malicious requests to bypass access restrictions, potentially allowing them to view sensitive information, including device call logs containing names, usernames, and phone numbers of users.
Recommendations
For Cisco IP Phones Series 7800 and Series 8800, consider restricting access to the web-based management interface until a fix is available.
As a temporary workaround, limit the exposure of the device to the internet and restrict access to the Web Access feature to minimize the risk of exploitation.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Incorrect Authorization
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Cisco Ip Phones Series 7800
Cisco Ip Phones Series 8800