PT-2020-2964 · Cisco · Cisco Ip Phones Series 7800+1

Oguzhan Karaman

·

Published

2020-06-17

·

Updated

2021-08-06

·

CVE-2020-3360

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Cisco IP Phones Series 7800 and Series 8800 (affected versions not specified)
Description A vulnerability in the Web Access feature could allow an unauthenticated, remote attacker to view sensitive information on an affected device. This issue is due to improper access controls on the web-based management interface. An attacker could exploit this by sending malicious requests to bypass access restrictions, potentially allowing them to view sensitive information, including device call logs containing names, usernames, and phone numbers of users.
Recommendations For Cisco IP Phones Series 7800 and Series 8800, consider restricting access to the web-based management interface until a fix is available. As a temporary workaround, limit the exposure of the device to the internet and restrict access to the Web Access feature to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Incorrect Authorization

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2020-03121
CVE-2020-3360

Affected Products

Cisco Ip Phones Series 7800
Cisco Ip Phones Series 8800