8.6

CVE-2023-20018

A vulnerability in the web-based management interface of Cisco IP Phone 7800 and 8800 Series Phones could allow an unauthenticated, remote attacker to bypass authentication on an affected device.

 This vulnerability is due to insufficient validation of user-supplied input. An attacker could exploit this vulnerability by sending a crafted request to the web-based management interface. A successful exploit could allow the attacker to access certain parts of the web interface that would normally require authentication.

Data is provided by the National Vulnerability Database (NVD)
CiscoIp Phone 7800 Firmware Version < 14.1\(1\)sr2
   CiscoIp Phone 7800 Version-
CiscoIp Phone 7811 Firmware Version < 14.1\(1\)sr2
   CiscoIp Phone 7811 Version-
CiscoIp Phone 7821 Firmware Version < 14.1\(1\)sr2
   CiscoIp Phone 7821 Version-
CiscoIp Phone 7832 Firmware Version < 14.1\(1\)sr2
   CiscoIp Phone 7832 Version-
CiscoIp Phone 7841 Firmware Version < 14.1\(1\)sr2
   CiscoIp Phone 7841 Version-
CiscoIp Phone 7861 Firmware Version < 14.1\(1\)sr2
   CiscoIp Phone 7861 Version-
CiscoIp Phone 8800 Firmware Version < 14.1\(1\)sr2
   CiscoIp Phone 8800 Version-
CiscoIp Phone 8811 Firmware Version < 14.1\(1\)sr2
   CiscoIp Phone 8811 Version-
CiscoIp Phone 8821 Firmware Version < 14.1\(1\)sr2
   CiscoIp Phone 8821 Version-
CiscoIp Phone 8821-ex Firmware Version < 14.1\(1\)sr2
   CiscoIp Phone 8821-ex Version-
CiscoIp Phone 8831 Firmware Version < 14.1\(1\)sr2
   CiscoIp Phone 8831 Version-
CiscoIp Phone 8832 Firmware Version < 14.1\(1\)sr2
   CiscoIp Phone 8832 Version-
CiscoIp Phone 8841 Firmware Version < 14.1\(1\)sr2
   CiscoIp Phone 8841 Version-
CiscoIp Phone 8845 Firmware Version < 14.1\(1\)sr2
   CiscoIp Phone 8845 Version-
CiscoIp Phone 8851 Firmware Version < 14.1\(1\)sr2
   CiscoIp Phone 8851 Version-
CiscoIp Phone 8861 Firmware Version < 14.1\(1\)sr2
   CiscoIp Phone 8861 Version-
CiscoIp Phone 8865 Firmware Version < 14.1\(1\)sr2
   CiscoIp Phone 8865 Version-
CiscoIp Phones 8832 Firmware Version < 14.1\(1\)sr2
   CiscoIp Phones 8832 Version-
CiscoUnified Ip Phone 8851nr Firmware Version < 14.1\(1\)sr2
   CiscoUnified Ip Phone 8851nr Version-
CiscoUnified Ip Phone 8865nr Firmware Version < 14.1\(1\)sr2
   CiscoUnified Ip Phone 8865nr Version-
CiscoWireless Ip Phone 8821 Firmware Version < 11.0\(6\)sr4
   CiscoWireless Ip Phone 8821 Version-
CiscoWireless Ip Phone 8821-ex Firmware Version < 11.0\(6\)sr4
   CiscoWireless Ip Phone 8821-ex Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.08% 0.209
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 6.5 3.9 2.5
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
psirt@cisco.com 8.6 3.9 4.7
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H
CWE-288 Authentication Bypass Using an Alternate Path or Channel

The product requires authentication, but the product has an alternate path or channel that does not require authentication.

CWE-863 Incorrect Authorization

The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.