First published: Fri Mar 03 2023(Updated: )
Multiple vulnerabilities in the web-based management interface of certain Cisco IP Phones could allow an unauthenticated, remote attacker to execute arbitrary code or cause a denial of service (DoS) condition. For more information about these vulnerabilities, see the Details section of this advisory.
Credit: ykramarz@cisco.com
Affected Software | Affected Version | How to fix |
---|---|---|
Cisco Ip Phone 6871 Firmware | <11.3.7sr1 | |
Cisco Ip Phone 6871 | ||
Cisco Ip Phone 6861 Firmware | <11.3.7sr1 | |
Cisco Ip Phone 6861 | ||
Cisco Ip Phone 6851 Firmware | <11.3.7sr1 | |
Cisco Ip Phone 6851 | ||
Cisco Ip Phone 6841 Firmware | <11.3.7sr1 | |
Cisco Ip Phone 6841 | ||
Cisco Ip Phone 6825 Firmware | <11.3.7sr1 | |
Cisco Ip Phone 6825 | ||
Cisco Ip Phone 7861 Firmware | <11.3.7sr1 | |
Cisco IP Phone 7861 | ||
Cisco Ip Phone 7841 Firmware | <11.3.7sr1 | |
Cisco Ip Phone 7841 | ||
Cisco Ip Phone 7832 Firmware | <11.3.7sr1 | |
Cisco Ip Phone 7832 | ||
Cisco Ip Phone 7821 Firmware | <11.3.7sr1 | |
Cisco Ip Phone 7821 | ||
Cisco Ip Phone 7811 Firmware | <11.3.7sr1 | |
Cisco Ip Phone 7811 | ||
Cisco Ip Phone 8865 Firmware | <11.3.7sr1 | |
Cisco Ip Phone 8865 | ||
Cisco Ip Phone 8861 Firmware | <11.3.7sr1 | |
Cisco Ip Phone 8861 | ||
Cisco Ip Phone 8851 Firmware | <11.3.7sr1 | |
Cisco IP Phone 8851 | ||
Cisco Ip Phone 8845 Firmware | <11.3.7sr1 | |
Cisco Ip Phone 8845 | ||
Cisco Ip Phone 8841 Firmware | <11.3.7sr1 | |
Cisco Ip Phone 8841 | ||
Cisco Ip Phone 8832 Firmware | <11.3.7sr1 | |
Cisco Ip Phone 8832 | ||
Cisco Ip Phone 8811 Firmware | <11.3.7sr1 | |
Cisco Ip Phone 8811 | ||
Cisco Ip Phone 8831 Firmware | <11.3.7sr1 | |
Cisco Ip Phone 8831 | ||
Cisco Unified Ip Phone 7945g Firmware | <11.3.7sr1 | |
Cisco Unified Ip Phone 7945g | ||
Cisco Unified Ip Phone 7965g Firmware | <11.3.7sr1 | |
Cisco Unified Ip Phone 7965g | ||
Cisco Unified Ip Phone 7975g Firmware | <11.3.7sr1 | |
Cisco Unified Ip Phone 7975g |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-20079 is a vulnerability in the web-based management interface of certain Cisco IP Phones that could allow an unauthenticated, remote attacker to execute arbitrary code or cause a denial of service (DoS) condition.
CVE-2023-20079 has a severity rating of 7.5, which is considered critical.
CVE-2023-20079 affects Cisco IP Phone models 6871, 6861, 6851, 6841, 6825, 7861, 7841, 7832, 7821, 7811, 8865, 8861, 8851, 8845, 8841, 8832, 8811, and 8831.
To fix CVE-2023-20079, update the firmware of the affected Cisco IP Phones to version 11.3.7sr1 or later.
More information about CVE-2023-20079 can be found in the advisory at https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ip-phone-cmd-inj-KMFynVcP.