CERT-In Vulnerability Note
CIVN-2023-0073
Multiple Vulnerabilities in Cisco IP Phone
Original Issue Date:March 14, 2023
Severity Rating: CRITICAL
Component Affected
- IP Phone 6800 Series , IP Phone 7800 Series , IP Phone 8800 with Multiplatform Firmware
- Unified IP Conference Phone 8831
Overview
Multiple vulnerabilities have been reported in web-based management interface of certain Cisco IP Phones could allow an unauthenticated, remote attacker to execute arbitrary codethat are executed with root privileges or cause a denial of service (DoS) condition.
Description
These vulnerabilities exist in the web-based management interface of Cisco IP Phone 6800, 7800, and 8800 Series Multiplatform Phones, as well as Cisco Unified IP Conference Phone 8831 due to insufficient validation of user-supplied input.An attacker could exploit these vulnerabilities by sending a crafted request to the web-based management interface
Successful exploitation of these vulnerabilities could allow the attacker to execute arbitrary commands on the underlying operating system of an affected device to cause a DoS condition.
Solution
Apply appropriate updates as mentioned in:
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ip-phone-cmd-inj-KMFynVcP
Vendor Information
CISCO
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ip-phone-cmd-inj-KMFynVcP
References
CISCO
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ip-phone-cmd-inj-KMFynVcP
CVE Name
CVE-2023-20078
CVE-2023-20079
Disclaimer
The information provided herein is on "as is" basis, without warranty of any kind.
Contact Information
Email: info@cert-in.org.in Phone: +91-11-24368572
Postal address
Indian Computer Emergency Response Team (CERT-In) Ministry of Electronics and Information Technology Government of India Electronics Niketan 6, CGO Complex, Lodhi Road, New Delhi - 110 003 India
|