A vulnerability in the Web Access feature of Cisco IP Phones Series 7800 and Series 8800 could allow an unauthenticated, remote attacker to view sensitive information on an affected device. The vulnerability is due to improper access controls on the web-based management interface of an affected device. An attacker could exploit this vulnerability by sending malicious requests to the device, which could allow the attacker to bypass access restrictions. A successful attack could allow the attacker to view sensitive information, including device call logs that contain names, usernames, and phone numbers of users of the device.

Project Subscriptions

Vendors Products
Unified Ip Phone 6901 Subscribe
Unified Ip Phone 6901 Firmware Subscribe
Unified Ip Phone 6911 Subscribe
Unified Ip Phone 6911 Firmware Subscribe
Unified Ip Phone 6921 Subscribe
Unified Ip Phone 6921 Firmware Subscribe
Unified Ip Phone 6941 Subscribe
Unified Ip Phone 6941 Firmware Subscribe
Unified Ip Phone 6945 Subscribe
Unified Ip Phone 6945 Firmware Subscribe
Unified Ip Phone 6961 Subscribe
Unified Ip Phone 6961 Firmware Subscribe
Unified Ip Phone 7811 Subscribe
Unified Ip Phone 7811 Firmware Subscribe
Unified Ip Phone 7821 Subscribe
Unified Ip Phone 7821 Firmware Subscribe
Unified Ip Phone 7832 Subscribe
Unified Ip Phone 7832 Firmware Subscribe
Unified Ip Phone 7841 Subscribe
Unified Ip Phone 7841 Firmware Subscribe
Unified Ip Phone 7861 Subscribe
Unified Ip Phone 7861 Firmware Subscribe
Unified Ip Phone 7906g Subscribe
Unified Ip Phone 7906g Firmware Subscribe
Unified Ip Phone 7911g Subscribe
Unified Ip Phone 7911g Firmware Subscribe
Unified Ip Phone 7931g Subscribe
Unified Ip Phone 7931g Firmware Subscribe
Unified Ip Phone 7937g Subscribe
Unified Ip Phone 7937g Firmware Subscribe
Unified Ip Phone 7940g Subscribe
Unified Ip Phone 7940g Firmware Subscribe
Unified Ip Phone 7941g Subscribe
Unified Ip Phone 7941g Firmware Subscribe
Unified Ip Phone 7942g Subscribe
Unified Ip Phone 7942g Firmware Subscribe
Unified Ip Phone 7945g Subscribe
Unified Ip Phone 7945g Firmware Subscribe
Unified Ip Phone 7960g Subscribe
Unified Ip Phone 7960g Firmware Subscribe
Unified Ip Phone 7961g Subscribe
Unified Ip Phone 7961g Firmware Subscribe
Unified Ip Phone 7962g Subscribe
Unified Ip Phone 7962g Firmware Subscribe
Unified Ip Phone 7965g Subscribe
Unified Ip Phone 7965g Firmware Subscribe
Unified Ip Phone 7975g Subscribe
Unified Ip Phone 7975g Firmware Subscribe
Unified Ip Phone 8811 Subscribe
Unified Ip Phone 8811 Firmware Subscribe
Unified Ip Phone 8841 Subscribe
Unified Ip Phone 8841 Firmware Subscribe
Unified Ip Phone 8845 Subscribe
Unified Ip Phone 8845 Firmware Subscribe
Unified Ip Phone 8851 Subscribe
Unified Ip Phone 8851 Firmware Subscribe
Unified Ip Phone 8851nr Subscribe
Unified Ip Phone 8851nr Firmware Subscribe
Unified Ip Phone 8861 Subscribe
Unified Ip Phone 8861 Firmware Subscribe
Unified Ip Phone 8865 Subscribe
Unified Ip Phone 8865 Firmware Subscribe
Unified Ip Phone 8865nr Subscribe
Unified Ip Phone 8865nr Firmware Subscribe
Unified Ip Phone 8941 Subscribe
Unified Ip Phone 8941 Firmware Subscribe
Unified Ip Phone 8945 Subscribe
Unified Ip Phone 8945 Firmware Subscribe
Unified Ip Phone 8961 Subscribe
Unified Ip Phone 8961 Firmware Subscribe
Unified Ip Phone 9951 Subscribe
Unified Ip Phone 9951 Firmware Subscribe
Unified Ip Phone 9971 Subscribe
Unified Ip Phone 9971 Firmware Subscribe
Advisories
Source ID Title
EUVD EUVD EUVD-2020-24631 A vulnerability in the Web Access feature of Cisco IP Phones Series 7800 and Series 8800 could allow an unauthenticated, remote attacker to view sensitive information on an affected device. The vulnerability is due to improper access controls on the web-based management interface of an affected device. An attacker could exploit this vulnerability by sending malicious requests to the device, which could allow the attacker to bypass access restrictions. A successful attack could allow the attacker to view sensitive information, including device call logs that contain names, usernames, and phone numbers of users of the device.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Fri, 15 Nov 2024 17:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: cisco

Published:

Updated: 2024-11-15T17:05:37.576Z

Reserved: 2019-12-12T00:00:00

Link: CVE-2020-3360

cve-icon Vulnrichment

Updated: 2024-08-04T07:30:58.207Z

cve-icon NVD

Status : Modified

Published: 2020-06-18T03:15:14.403

Modified: 2024-11-21T05:30:52.567

Link: CVE-2020-3360

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses