CVE-2024-20445
Last modified
CVE-2024-20445 is a medium-severity vulnerability rated 5.3/10 on the CVSS scale. A vulnerability in the web UI of Cisco Desk Phone 9800 Series, Cisco IP Phone 7800 and 8800 Series, and Cisco Video Phone 8875 could allow an unauthenticated, remote attacker to access sensitive information on an affected device. This vulnerability is due to improper storage of sensitive information within the web UI of Session Initiation Protocol (SIP)-based phone loads. An attacker could exploit this vulnerability by browsing to the IP address of a device that has Web Access enabled. EPSS estimates a 0.45% chance of exploitation in the next 30 days.
Description
A vulnerability in the web UI of Cisco Desk Phone 9800 Series, Cisco IP Phone 7800 and 8800 Series, and Cisco Video Phone 8875 could allow an unauthenticated, remote attacker to access sensitive information on an affected device. This vulnerability is due to improper storage of sensitive information within the web UI of Session Initiation Protocol (SIP)-based phone loads. An attacker could exploit this vulnerability by browsing to the IP address of a device that has Web Access enabled. A successful exploit could allow the attacker to access sensitive information, including incoming and outgoing call records. Note: Web Access is disabled by default.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Cisco | Desk Phone 9841 Firmware | 3.1\(1\) |
| Cisco | Desk Phone 9851 Firmware | 3.1\(1\) |
| Cisco | Desk Phone 9861 Firmware | 3.1\(1\) |
| Cisco | Desk Phone 9871 Firmware | 3.1\(1\) |
| Cisco | Ip Conference Phone 7832 Firmware | < 14.3\(1\) |
| Cisco | Ip Conference Phone 8831 Firmware | < 14.3\(1\) |
| Cisco | Ip Conference Phone 8832 Firmware | < 14.3\(1\) |
| Cisco | Ip Phone 7811 Firmware | < 14.3\(1\) |
| Cisco | Ip Phone 7821 Firmware | < 14.3\(1\) |
| Cisco | Ip Phone 7841 Firmware | < 14.3\(1\) |
| Cisco | Ip Phone 7861 Firmware | < 14.3\(1\) |
| Cisco | Ip Phone 8811 Firmware | < 14.3\(1\) |
| Cisco | Ip Phone 8841 Firmware | < 14.3\(1\) |
| Cisco | Ip Phone 8845 Firmware | < 14.3\(1\) |
| Cisco | Ip Phone 8851 Firmware | < 14.3\(1\) |
| Cisco | Ip Phone 8851nr Firmware | < 14.3\(1\) |
| Cisco | Ip Phone 8861 Firmware | < 14.3\(1\) |
| Cisco | Video Phone 8875 Firmware | < 2.3\(1\) |
| Cisco | Video Phone 8875 Firmware | 2.3\(1\) |
References
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2024-20445?
How severe is CVE-2024-20445?
How do I fix CVE-2024-20445?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2024
- CVE-2024-2044pgAdmin <= 8.3 is affected by a path-traversal vulnerability…9.9
- CVE-2024-20440A vulnerability in Cisco Smart Licensing Utility could allow…7.5
- CVE-2024-20441A vulnerability in a specific REST API endpoint of Cisco NDF…6.5
- CVE-2024-20442A vulnerability in the REST API endpoints of Cisco Nexus Das…5.4
- CVE-2024-20443A vulnerability in the web-based management interface of Cis…5.4
- CVE-2024-20444A vulnerability in Cisco Nexus Dashboard Fabric Controller (…5.5
- CVE-2024-20446A vulnerability in the DHCPv6 relay agent of Cisco NX-OS Sof…8.6
- CVE-2024-20448A vulnerability in the Cisco Nexus Dashboard Fabric Controll…8.6
- CVE-2024-20449A vulnerability in Cisco Nexus Dashboard Fabric Controller (…8.8
- CVE-2024-2045Session version 1.17.5 allows obtaining internal application…5.5
- CVE-2024-20450Multiple vulnerabilities in the web-based management interfa…9.8
- CVE-2024-20451Multiple vulnerabilities in the web-based management interfa…7.5
Are you affected by CVE-2024-20445?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
