CVE-2023-20079: Cisco IP Phone 6800, 7800, 7900, and 8800 Series Web UI Vulnerabilities
Multiple vulnerabilities in the web-based management interface of certain Cisco IP Phones could allow an unauthenticated, remote attacker to execute arbitrary code or cause a denial of service (DoS) condition. For more information about these vulnerabilities, see the Details section of this advisory.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2023-20079?
CVE-2023-20079 is a vulnerability in the web-based management interface of certain Cisco IP Phones that could allow an unauthenticated, remote attacker to execute arbitrary code or cause a denial of service (DoS) condition.
How severe is CVE-2023-20079?
CVE-2023-20079 has a severity rating of 7.5, which is considered critical.
Which Cisco IP Phone models are affected by CVE-2023-20079?
CVE-2023-20079 affects Cisco IP Phone models 6871, 6861, 6851, 6841, 6825, 7861, 7841, 7832, 7821, 7811, 8865, 8861, 8851, 8845, 8841, 8832, 8811, and 8831.
How do I fix CVE-2023-20079?
To fix CVE-2023-20079, update the firmware of the affected Cisco IP Phones to version 11.3.7sr1 or later.
Where can I find more information about CVE-2023-20079?
More information about CVE-2023-20079 can be found in the advisory at https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ip-phone-cmd-inj-KMFynVcP.