PT-2024-3224 · Cisco · Cisco Ip Phone 6800+4
Andras Kosztyu
+3
·
Published
2024-05-01
·
Updated
2026-01-05
·
CVE-2024-20376
CVSS v2.0
7.8
High
| Vector | AV:N/AC:L/Au:N/C:N/I:N/A:C |
Name of the Vulnerable Software and Affected Versions
Cisco IP Phone firmware (affected versions not specified)
Cisco IP Phone 6800, Cisco IP Phone 7800, Cisco IP Phone 8800, and Cisco IP Phone 8875 (affected versions not specified)
Description
A vulnerability in the web-based management interface of Cisco IP Phone firmware could allow an unauthenticated, remote attacker to cause an affected device to reload, resulting in a DoS condition. This vulnerability is due to insufficient validation of user-supplied input. An attacker could exploit this vulnerability by sending a crafted request to the web-based management interface of an affected device. A successful exploit could allow the attacker to cause the affected device to reload.
Recommendations
For Cisco IP Phone firmware, update to a patched version to resolve the issue.
For Cisco IP Phone 6800, Cisco IP Phone 7800, Cisco IP Phone 8800, and Cisco IP Phone 8875, update to a patched version to resolve the issue.
As a temporary workaround, consider restricting access to the web-based management interface until a patch is available.
Avoid using the web-based management interface until the issue is resolved.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
DoS
Memory Corruption
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Cisco Ip Phone
Cisco Ip Phone 6800
Cisco Ip Phone 7800
Cisco Ip Phone 8800
Cisco Ip Phone 8875