CVE-2024-20445: Cisco IP Phone 7800, 8800, and 9800 Series Information Disclosure Vulnerability

Published Nov 6, 2024
·
Updated

A vulnerability in the web UI of Cisco Desk Phone 9800 Series, Cisco IP Phone 7800 and 8800 Series, and Cisco Video Phone 8875 could allow an unauthenticated, remote attacker to access sensitive information on an affected device. This vulnerability is due to improper storage of sensitive information within the web UI of Session Initiation Protocol (SIP)-based phone loads. An attacker could exploit this vulnerability by browsing to the IP address of a device that has Web Access enabled. A successful exploit could allow the attacker to access sensitive information, including incoming and outgoing call records. Note: Web Access is disabled by default.

Affected Software

46 affected components
Cisco Desk Phone 9800 Series
Cisco IP Phone 7800 Series
Cisco IP Phone 8800 Series
Cisco Video Phone 8875
All of the following
Any of the following
Cisco Desk Phone 9841 Firmware=3.1\(1\)
Cisco Desk Phone 9841 Firmware=3.1\(1\)-sr1
Cisco Desk Phone 9841
All of the following
Any of the following
Cisco Desk Phone 9851 Firmware=3.1\(1\)
Cisco Desk Phone 9851 Firmware=3.1\(1\)-sr1
Cisco Desk Phone 9851
All of the following
Any of the following
Cisco Desk Phone 9861 Firmware=3.1\(1\)
Cisco Desk Phone 9861 Firmware=3.1\(1\)-sr1
Cisco Desk Phone 9861
All of the following
Any of the following
Cisco Desk Phone 9871 Firmware=3.1\(1\)
Cisco Desk Phone 9871 Firmware=3.1\(1\)-sr1
Cisco Desk Phone 9871
All of the following
Cisco Ip Conference Phone 7832 Firmware<14.3\(1\)
Cisco Ip Conference Phone 7832
All of the following
Cisco Ip Conference Phone 8831 Firmware<14.3\(1\)
Cisco Ip Conference Phone 8831
All of the following
Cisco Ip Conference Phone 8832 Firmware<14.3\(1\)
Cisco IP Conference Phone 8832
All of the following
Cisco Ip Phone 7811 Firmware<14.3\(1\)
Cisco Ip Phone 7811
All of the following
Cisco Ip Phone 7821 Firmware<14.3\(1\)
Cisco Ip Phone 7821
All of the following
Cisco Ip Phone 7841 Firmware<14.3\(1\)
Cisco Ip Phone 7841
All of the following
Cisco Ip Phone 7861 Firmware<14.3\(1\)
Cisco IP Phone 7861
All of the following
Cisco Ip Phone 8811 Firmware<14.3\(1\)
Cisco Ip Phone 8811
All of the following
Cisco Ip Phone 8841 Firmware<14.3\(1\)
Cisco Ip Phone 8841
All of the following
Cisco Ip Phone 8845 Firmware<14.3\(1\)
Cisco Ip Phone 8845
All of the following
Cisco Ip Phone 8851 Firmware<14.3\(1\)
Cisco IP Phone 8851
All of the following
Cisco Ip Phone 8851nr Firmware<14.3\(1\)
Cisco Ip Phone 8851nr
All of the following
Cisco Ip Phone 8861 Firmware<14.3\(1\)
Cisco Ip Phone 8861
All of the following
Any of the following
Cisco Video Phone 8875 Firmware<2.3\(1\)
Cisco Video Phone 8875 Firmware=2.3\(1\)
Cisco Video Phone 8875 Firmware=2.3\(1\)-sr1
Cisco Video Phone 8875

Event History

Nov 6, 2024
CVE Published
via MITRE·04:29 PM
Data Sourced
via MITRE·04:29 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·05:15 PM
DescriptionSeverityWeaknessAffected Software
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2024-20445?

CVE-2024-20445 is considered to have a high severity due to the potential for sensitive information disclosure.

2

How do I fix CVE-2024-20445?

To mitigate CVE-2024-20445, update the affected Cisco Desk Phone 9800 Series, Cisco IP Phone 7800 and 8800 Series, and Cisco Video Phone 8875 devices to the latest firmware released by Cisco.

3

Who is affected by CVE-2024-20445?

CVE-2024-20445 affects users of Cisco Desk Phone 9800 Series, Cisco IP Phone 7800 Series, Cisco IP Phone 8800 Series, and Cisco Video Phone 8875.

4

What type of vulnerability is CVE-2024-20445?

CVE-2024-20445 is a remote information disclosure vulnerability that can be exploited by unauthenticated attackers.

5

What can an attacker do with CVE-2024-20445?

An attacker exploiting CVE-2024-20445 can access sensitive information stored on the affected devices.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203