PT-2024-3224 · Cisco · Cisco Ip Phone 6800+4

Andras Kosztyu

+3

·

Published

2024-05-01

·

Updated

2026-01-05

·

CVE-2024-20376

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions Cisco IP Phone firmware (affected versions not specified) Cisco IP Phone 6800, Cisco IP Phone 7800, Cisco IP Phone 8800, and Cisco IP Phone 8875 (affected versions not specified)
Description A vulnerability in the web-based management interface of Cisco IP Phone firmware could allow an unauthenticated, remote attacker to cause an affected device to reload, resulting in a DoS condition. This vulnerability is due to insufficient validation of user-supplied input. An attacker could exploit this vulnerability by sending a crafted request to the web-based management interface of an affected device. A successful exploit could allow the attacker to cause the affected device to reload.
Recommendations For Cisco IP Phone firmware, update to a patched version to resolve the issue. For Cisco IP Phone 6800, Cisco IP Phone 7800, Cisco IP Phone 8800, and Cisco IP Phone 8875, update to a patched version to resolve the issue. As a temporary workaround, consider restricting access to the web-based management interface until a patch is available. Avoid using the web-based management interface until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

DoS

Memory Corruption

Weakness Enumeration

Related Identifiers

BDU:2024-03451
CVE-2024-20376

Affected Products

Cisco Ip Phone
Cisco Ip Phone 6800
Cisco Ip Phone 7800
Cisco Ip Phone 8800
Cisco Ip Phone 8875