CVE-2023-20018: High severity cisco ip conference phone 7800 firmware vulnerability
A vulnerability in the web-based management interface of Cisco IP Phone 7800 and 8800 Series Phones could allow an unauthenticated, remote attacker to bypass authentication on an affected device. This vulnerability is due to insufficient validation of user-supplied input. An attacker could exploit this vulnerability by sending a crafted request to the web-based management interface. A successful exploit could allow the attacker to access certain parts of the web interface that would normally require authentication.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2023-20018.
What is the severity level of CVE-2023-20018?
The severity level of CVE-2023-20018 is high, with a CVSS score of 6.5.
Which Cisco IP Phone series are affected by CVE-2023-20018?
CVE-2023-20018 affects the Cisco IP Phone 7800 and 8800 Series Phones.
How can an attacker exploit CVE-2023-20018?
An attacker can exploit CVE-2023-20018 by bypassing authentication on the affected device through the web-based management interface.
Where can I find more information about CVE-2023-20018?
You can find more information about CVE-2023-20018 in the Cisco Security Advisory at this link: https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ip-phone-auth-bypass-pSqxZRPR