PT-2024-8287 · Cisco · Cisco Ip Phone 6800 Series+4
Ian Thorne
·
Published
2024-11-06
·
Updated
2026-01-05
·
CVE-2024-20533
CVSS v2.0
5.5
Medium
| Vector | AV:N/AC:L/Au:S/C:P/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
Cisco Desk Phone 9800 Series (affected versions not specified)
Cisco IP Phone 6800 Series (affected versions not specified)
Cisco IP Phone 7800 Series (affected versions not specified)
Cisco IP Phone 8800 Series (affected versions not specified)
Cisco Video Phone 8875 (affected versions not specified)
Description
A vulnerability in the web UI of the affected devices could allow an authenticated, remote attacker to conduct stored cross-site scripting (XSS) attacks against users. This issue exists because the web UI does not properly validate user-supplied input. An attacker could exploit this by injecting malicious code into specific pages of the interface, potentially allowing the execution of arbitrary script code in the context of the affected interface or access to sensitive, browser-based information. Note that to exploit this, Web Access must be enabled on the phone and the attacker must have Admin credentials on the device. Web Access is disabled by default.
Recommendations
For Cisco Desk Phone 9800 Series, consider disabling Web Access until a patch is available.
For Cisco IP Phone 6800 Series, restrict access to the web UI for non-admin users until a fix is applied.
For Cisco IP Phone 7800 Series, avoid using the web UI for sensitive operations until the issue is resolved.
For Cisco IP Phone 8800 Series, limit the use of the web interface to necessary administrative tasks only until a patch is released.
For Cisco Video Phone 8875, disable the web UI temporarily as a mitigation measure until a fix is available.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Cisco Desk Phone 9800 Series
Cisco Ip Phone 6800 Series
Cisco Ip Phone 7800 Series
Cisco Ip Phone 8800 Series
Cisco Video Phone 8875