Multiple vulnerabilities in Cisco IP Phone 6800, 7800, 8800, Desk Phone 9800 and Video Phone 8875 Series Phones with Multiplatform Firmware



Risk Low
Patch available YES
Number of vulnerabilities 2
CVE-ID CVE-2024-20533
CVE-2024-20534
CWE-ID CWE-79
Exploitation vector Network
Public exploit N/A
Vulnerable software
Subscribe
Desk Phone 9800 Series with Multiplatform Firmware
Hardware solutions / Office equipment, IP-phones, print servers

IP Phone 8800 Series with Multiplatform Firmware
Hardware solutions / Office equipment, IP-phones, print servers

Video Phone 8875 with Multiplatform Firmware
Hardware solutions / Office equipment, IP-phones, print servers

IP Phone 6800 Series with Multiplatform Firmware
Other software / Other software solutions

IP Phone 7800 Series with Multiplatform Firmware
Other software / Other software solutions

Cisco Multiplatform Firmware
Hardware solutions / Firmware

Vendor Cisco Systems, Inc

Security Bulletin

This security bulletin contains information about 2 vulnerabilities.

1) Stored cross-site scripting

EUVDB-ID: #VU100093

Risk: Low

CVSSv3.1: 5.6 [CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N/E:U/RL:O/RC:C]

CVE-ID: CVE-2024-20533

CWE-ID: CWE-79 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Exploit availability: No

Description

The disclosed vulnerability allows a remote attacker to perform cross-site scripting (XSS) attacks.

The vulnerability exists due to insufficient sanitization of user-supplied data in the web UI. A remote user can inject and execute arbitrary HTML and script code in user's browser in context of vulnerable website.

Successful exploitation of this vulnerability may allow a remote attacker to steal potentially sensitive information, change appearance of the web page, perform phishing and drive-by-download attacks.

Mitigation

Install updates from vendor's website.

Vulnerable software versions

Desk Phone 9800 Series with Multiplatform Firmware: All versions

IP Phone 6800 Series with Multiplatform Firmware: All versions

IP Phone 7800 Series with Multiplatform Firmware: All versions

IP Phone 8800 Series with Multiplatform Firmware: All versions

Video Phone 8875 with Multiplatform Firmware: All versions

Cisco Multiplatform Firmware: 2.3(1)SR1 - 12.0.5SR1

CPE2.3 External links

http://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-mpp-xss-8tAV2TvF


Q & A

Can this vulnerability be exploited remotely?

Yes. This vulnerability can be exploited by a remote authenticated user via the Internet.

How the attacker can exploit this vulnerability?

The attacker would have to send a specially crafted request to the affected device in order to exploit this vulnerability.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.

2) Stored cross-site scripting

EUVDB-ID: #VU100094

Risk: Low

CVSSv3.1: 5.6 [CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N/E:U/RL:O/RC:C]

CVE-ID: CVE-2024-20534

CWE-ID: CWE-79 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Exploit availability: No

Description

The disclosed vulnerability allows a remote attacker to perform cross-site scripting (XSS) attacks.

The vulnerability exists due to insufficient sanitization of user-supplied data in the web UI. A remote user can inject and execute arbitrary HTML and script code in user's browser in context of vulnerable website.

Successful exploitation of this vulnerability may allow a remote attacker to steal potentially sensitive information, change appearance of the web page, perform phishing and drive-by-download attacks.

Mitigation

Install updates from vendor's website.

Vulnerable software versions

Desk Phone 9800 Series with Multiplatform Firmware: All versions

IP Phone 6800 Series with Multiplatform Firmware: All versions

IP Phone 7800 Series with Multiplatform Firmware: All versions

IP Phone 8800 Series with Multiplatform Firmware: All versions

Video Phone 8875 with Multiplatform Firmware: All versions

Cisco Multiplatform Firmware: 2.3(1)SR1 - 12.0.5SR1

CPE2.3 External links

http://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-mpp-xss-8tAV2TvF


Q & A

Can this vulnerability be exploited remotely?

Yes. This vulnerability can be exploited by a remote authenticated user via the Internet.

How the attacker can exploit this vulnerability?

The attacker would have to send a specially crafted request to the affected device in order to exploit this vulnerability.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.



###SIDEBAR###