CVE-2025-20351
- EPSS 0.05%
- Veröffentlicht 15.10.2025 16:15:18
- Zuletzt bearbeitet 04.12.2025 21:26:51
A vulnerability in the web UI of Cisco Desk Phone 9800 Series, Cisco IP Phone 7800 and 8800 Series, and Cisco Video Phone 8875 running Cisco SIP Software could allow an unauthenticated, remote attacker to conduct XSS attacks against a user of the web...
CVE-2025-20350
- EPSS 0.09%
- Veröffentlicht 15.10.2025 16:15:10
- Zuletzt bearbeitet 04.12.2025 21:29:46
A vulnerability in the web UI of Cisco Desk Phone 9800 Series, Cisco IP Phone 7800 and 8800 Series, and Cisco Video Phone 8875 running Cisco SIP Software could allow an unauthenticated, remote attacker to cause a DoS condition on an affected device. ...
CVE-2024-20357
- EPSS 0.4%
- Veröffentlicht 01.05.2024 17:15:28
- Zuletzt bearbeitet 21.11.2024 08:52:27
A vulnerability in the XML service of Cisco IP Phone firmware could allow an unauthenticated, remote attacker to initiate phone calls on an affected device. This vulnerability exists because bounds-checking does not occur while parsing XML reque...
CVE-2024-20376
- EPSS 0.35%
- Veröffentlicht 01.05.2024 17:15:28
- Zuletzt bearbeitet 21.11.2024 08:52:29
A vulnerability in the web-based management interface of Cisco IP Phone firmware could allow an unauthenticated, remote attacker to cause an affected device to reload, resulting in a DoS condition. This vulnerability is due to insufficient valid...
CVE-2024-20378
- EPSS 0.43%
- Veröffentlicht 01.05.2024 17:15:28
- Zuletzt bearbeitet 21.11.2024 08:52:30
A vulnerability in the web-based management interface of Cisco IP Phone firmware could allow an unauthenticated, remote attacker to retrieve sensitive information from an affected device. This vulnerability is due to a lack of authentication for...
CVE-2023-20221
- EPSS 0.39%
- Veröffentlicht 16.08.2023 22:15:11
- Zuletzt bearbeitet 21.11.2024 07:40:55
A vulnerability in the web-based management interface of Cisco IP Phone 6800, 7800, and 8800 Series with Multiplatform Firmware could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack against a user of th...