4.8

CVE-2024-20534

A vulnerability in the web UI of Cisco Desk Phone 9800 Series, Cisco IP Phone 6800, 7800, and 8800 Series, and Cisco Video Phone 8875 with Cisco Multiplatform Firmware could allow an authenticated, remote attacker to conduct stored cross-site scripting (XSS) attacks against users.

This vulnerability exists because the web UI of an affected device does not properly validate user-supplied input. An attacker could exploit this vulnerability by injecting malicious code into specific pages of the interface. A successful exploit could allow the attacker to execute arbitrary script code in the context of the affected interface or access sensitive, browser-based information.
Note: To exploit this vulnerability, Web Access must be enabled on the phone and the attacker must have Admin credentials on the device. Web Access is disabled by default.

Verknüpft mit AI von unstrukturierten Daten zu bestehenden CPE der NVD
Diese Information steht angemeldeten Benutzern zur Verfügung.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerCisco
Produkt Cisco IP Phones with Multiplatform Firmware
Default Statusunknown
Version 11.1.2
Status affected
Version 11.2.1
Status affected
Version 11.2.3
Status affected
Version 11.2.2
Status affected
Version 11.2.3 MSR1-1
Status affected
Version 11.1.2 MSR1-1
Status affected
Version 11.1.1
Status affected
Version 11.1.2 MSR3-1
Status affected
Version 11.0.0
Status affected
Version 11.1.1 MSR1-1
Status affected
Version 11.0.1
Status affected
Version 11.1.1 MSR2-1
Status affected
Version 11.2.4
Status affected
Version 11.0.1 MSR1-1
Status affected
Version 11.0.2
Status affected
Version 11.3.1
Status affected
Version 11.3.1 MSR1-3
Status affected
Version 11.3.2
Status affected
Version 11.3.1 MSR2-6
Status affected
Version 11-3-1MSR2UPG
Status affected
Version 4.7.1
Status affected
Version 4.6 MSR1
Status affected
Version 11.3.1 MSR3-3
Status affected
Version 4.8.1
Status affected
Version 11.3.3
Status affected
Version 11.3.1 MSR4-1
Status affected
Version 11.3.4
Status affected
Version 4.8.1 SR1
Status affected
Version 11.3.5
Status affected
Version 11.3.3 MSR1
Status affected
Version 5.0.1
Status affected
Version 11.3.3 MSR2
Status affected
Version 11.3.6
Status affected
Version 11-3-1MPPSR4UPG
Status affected
Version 11.3.6SR1
Status affected
Version 11.3.7
Status affected
Version 5.1.1
Status affected
Version 11.3.7SR1
Status affected
Version 12.0.1
Status affected
Version 12.0.2
Status affected
Version 11.3.7SR2
Status affected
Version 12.0.3
Status affected
Version 12.0.3SR1
Status affected
Version 12.0.4
Status affected
Version 12.0.4SR1
Status affected
Version 12.0.5
Status affected
Version 12.0.5SR1
Status affected
Version 12.0.3SR2
Status affected
HerstellerCisco
Produkt Cisco Session Initiation Protocol (SIP) Software
Default Statusunknown
Version 3.1(1)
Status affected
Version 3.0(1)
Status affected
Version 3.1(1)SR1
Status affected
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.06% 0.198
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
psirt@cisco.com 4.8 1.7 2.7
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N
CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.