5.9

CVE-2024-20357

A vulnerability in the XML service of Cisco IP Phone firmware could allow an unauthenticated, remote attacker to initiate phone calls on an affected device.  

 This vulnerability exists because bounds-checking does not occur while parsing XML requests. An attacker could exploit this vulnerability by sending a crafted XML request to an affected device. A successful exploit could allow the attacker to initiate calls or play sounds on the device.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
CiscoIp Phone 6871 With Multiplatform Firmware Version <= 12.0.4
   CiscoIp Phone 6871 Version-
CiscoIp Phone 7811 With Multiplatform Firmware Version <= 12.0.4
   CiscoIp Phone 7811 Version-
CiscoIp Phone 7821 With Multiplatform Firmware Version <= 12.0.4
   CiscoIp Phone 7821 Version-
CiscoIp Phone 7832 With Multiplatform Firmware Version <= 12.0.4
   CiscoIp Phone 7832 Version-
CiscoIp Phone 7841 With Multiplatform Firmware Version <= 12.0.4
   CiscoIp Phone 7841 Version-
CiscoIp Phone 7861 With Multiplatform Firmware Version <= 12.0.4
   CiscoIp Phone 7861 Version-
CiscoIp Phone 8811 With Multiplatform Firmware Version <= 12.0.4
   CiscoIp Phone 8811 Version-
CiscoIp Phone 8832 With Multiplatform Firmware Version <= 12.0.4
   CiscoIp Phone 8832 Version-
CiscoIp Phone 8841 With Multiplatform Firmware Version <= 12.0.4
   CiscoIp Phone 8841 Version-
CiscoIp Phone 8845 With Multiplatform Firmware Version <= 12.0.4
   CiscoIp Phone 8845 Version-
CiscoIp Phone 8851 With Multiplatform Firmware Version <= 12.0.4
   CiscoIp Phone 8851 Version-
CiscoIp Phone 8861 With Multiplatform Firmware Version <= 12.0.4
   CiscoIp Phone 8861 Version-
CiscoIp Phone 8865 With Multiplatform Firmware Version <= 12.0.4
   CiscoIp Phone 8865 Version-
CiscoVideo Phone 8875 Firmware Version < 2.3.1.0101
   CiscoVideo Phone 8875 Version-
CiscoIp Phone 6821 With Multiplatform Firmware Version <= 12.0.4
   CiscoIp Phone 6821 Version-
CiscoIp Phone 6841 With Multiplatform Firmware Version <= 12.0.4
   CiscoIp Phone 6841 Version-
CiscoIp Phone 6851 With Multiplatform Firmware Version <= 12.0.4
   CiscoIp Phone 6851 Version-
CiscoIp Phone 6861 With Multiplatform Firmware Version <= 12.0.4
   CiscoIp Phone 6861 Version-
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.61% 0.696
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
psirt@cisco.com 5.9 2.2 3.6
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N
CWE-787 Out-of-bounds Write

The product writes data past the end, or before the beginning, of the intended buffer.