CVE-2024-20357
A vulnerability in the XML service of Cisco IP Phone firmware could allow an unauthenticated, remote attacker to initiate phone calls on an affected device. This vulnerability exists because boun
Description
A vulnerability in the XML service of Cisco IP Phone firmware could allow an unauthenticated, remote attacker to initiate phone calls on an affected device. This vulnerability exists because bounds-checking does not occur while parsing XML requests. An attacker could exploit this vulnerability by sending a crafted XML request to an affected device. A successful exploit could allow the attacker to initiate calls or play sounds on the device.
Weakness: CWE-787
Affected products
| Vendor | Product | Category | Matched by |
|---|---|---|---|
| Cisco | Cisco IP Phones | Other Products | cna-assigner |
Vendor-reported products (14)
- Cisco · Cisco IP Phones with Multiplatform Firmware
- Cisco · Cisco PhoneOS
- cisco · ip_phone_6871_with_multiplatform_firmware
- cisco · ip_phone_6821_with_multiplatform_firmware
- cisco · ip_phone_6851_with_multiplatform_firmware
- cisco · ip_phone_7821_with_multiplatform_firmware
- cisco · ip_phone_6861_with_multiplatform_firmware
- cisco · ip_phone_6825_with_multiplatform_firmware
- cisco · ip_phone_6841_with_multiplatform_firmware
- cisco · ip_phone_7811_with_multiplatform_firmware
- cisco · ip_phone_7841_with_multiplatform_firmware
- cisco · ip_phone_7861_with_multiplatform_firmware
- cisco · ip_phone_8800_series_with_multiplatform_firmware
- cisco · video_phone_8875_firmware
Vendor advisory
cisco-sa-ipphone-multi-vulns-cXAhCvS
Cisco IP Phone 6800, 7800, and 8800 Series with Multiplatform Firmware Vulnerabilities
Cisco’s rating: High (advisory CVSS 7.5) · Published May 1, 2024
Bug IDs: CSCwi64037 , CSCwi64050 , CSCwi64064 , CSCwi64077 , CSCwi64082 , CSCwi64103
The vendor’s rating applies to the whole advisory and can differ from this CVE’s own CVSS severity. Where this comes from