CVE-2024-20533: Cisco IP Phone 6800, 7800, 8800, and 9800 Series with Multiplatform Firmware Stored Cross-Site Scripting Vulnerabilities

Published Nov 6, 2024
·
Updated

A vulnerability in the web UI of Cisco Desk Phone 9800 Series, Cisco IP Phone 6800, 7800, and 8800 Series, and Cisco Video Phone 8875 with Cisco Multiplatform Firmware could allow an authenticated, remote attacker to conduct stored cross-site scripting (XSS) attacks against users. This vulnerability exists because the web UI of an affected device does not properly validate user-supplied input. An attacker could exploit this vulnerability by injecting malicious code into specific pages of the interface. A successful exploit could allow the attacker to execute arbitrary script code in the context of the affected interface or access sensitive, browser-based information. Note: To exploit this vulnerability, Web Access must be enabled on the phone and the attacker must have Admin credentials on the device. Web Access is disabled by default.

Affected Software

58 affected components
Cisco Desk Phone 9800 Series
Cisco IP Phone 6800
Cisco IP Phone 7800
Cisco IP Phone 8800
Cisco Video Phone 8875
Cisco Multiplatform Firmware
All of the following
Any of the following
Cisco Desk Phone 9841 With Multiplatform Firmware=3.1\(1\)
Cisco Desk Phone 9841 With Multiplatform Firmware=3.1\(1\)-sr1
Cisco Desk Phone 9841
All of the following
Any of the following
Cisco Desk Phone 9851 With Multiplatform Firmware=3.1\(1\)
Cisco Desk Phone 9851 With Multiplatform Firmware=3.1\(1\)-sr1
Cisco Desk Phone 9851
All of the following
Any of the following
Cisco Desk Phone 9861 With Multiplatform Firmware=3.1\(1\)
Cisco Desk Phone 9861 With Multiplatform Firmware=3.1\(1\)-sr1
Cisco Desk Phone 9861
All of the following
Any of the following
Cisco Desk Phone 9871 With Multiplatform Firmware=3.1\(1\)
Cisco Desk Phone 9871 With Multiplatform Firmware=3.1\(1\)-sr1
Cisco Desk Phone 9871
All of the following
Cisco Ip Phone 6821 With Multiplatform Firmware=12.0\(5\)-sr1
Cisco Ip Phone 6821
All of the following
Cisco Ip Phone 6841 With Multiplatform Firmware=12.0\(5\)-sr1
Cisco Ip Phone 6841
All of the following
Cisco Ip Phone 6851 With Multiplatform Firmware=12.0\(5\)-sr1
Cisco Ip Phone 6851
All of the following
Cisco Ip Phone 6861 With Multiplatform Firmware=12.0\(5\)-sr1
Cisco Ip Phone 6861
All of the following
Cisco Ip Phone 6871 With Multiplatform Firmware=12.0\(5\)-sr1
Cisco Ip Phone 6871
All of the following
Cisco Ip Phone 7811 With Multiplatform Firmware=12.0\(5\)-sr1
Cisco Ip Phone 7811
All of the following
Cisco Ip Phone 7821 With Multiplatform Firmware=12.0\(5\)-sr1
Cisco Ip Phone 7821
All of the following
Cisco Ip Phone 7832 With Multiplatform Firmware=12.0\(5\)-sr1
Cisco Ip Phone 7832
All of the following
Cisco Ip Phone 7841 With Multiplatform Firmware=12.0\(5\)-sr1
Cisco Ip Phone 7841
All of the following
Cisco Ip Phone 7861 With Multiplatform Firmware=12.0\(5\)-sr1
Cisco IP Phone 7861
All of the following
Cisco Ip Phone 8811 With Multiplatform Firmware=12.0\(5\)-sr1
Cisco Ip Phone 8811
All of the following
Cisco Ip Phone 8832 With Multiplatform Firmware=12.0\(5\)-sr1
Cisco Ip Phone 8832
All of the following
Cisco Ip Phone 8841 With Multiplatform Firmware=12.0\(5\)-sr1
Cisco Ip Phone 8841
All of the following
Cisco Ip Phone 8845 With Multiplatform Firmware=12.0\(5\)-sr1
Cisco Ip Phone 8845
All of the following
Cisco Ip Phone 8851 With Multiplatform Firmware=12.0\(5\)-sr1
Cisco IP Phone 8851
All of the following
Cisco Ip Phone 8861 With Multiplatform Firmware=12.0\(5\)-sr1
Cisco Ip Phone 8861
All of the following
Cisco Ip Phone 8865 With Multiplatform Firmware=12.0\(5\)-sr1
Cisco Ip Phone 8865
All of the following
Any of the following
Cisco Video Phone 8875 With Multiplatform Firmware<2.3\(1\)
Cisco Video Phone 8875 With Multiplatform Firmware=2.3\(1\)
Cisco Video Phone 8875 With Multiplatform Firmware=2.3\(1\)-sr1
Cisco Video Phone 8875
All of the following
Cisco Ip Phone 8831 With Multiplatform Firmware
Cisco Ip Phone 8831

Event History

Nov 6, 2024
CVE Published
via MITRE·04:31 PM
Data Sourced
via MITRE·04:31 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·05:15 PM
DescriptionSeverityWeaknessAffected Software
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2024-20533?

CVE-2024-20533 is rated as a medium severity vulnerability.

2

How do I fix CVE-2024-20533?

To fix CVE-2024-20533, apply the latest firmware updates provided by Cisco for the affected devices.

3

Which products are affected by CVE-2024-20533?

CVE-2024-20533 affects Cisco Desk Phone 9800 Series, Cisco IP Phone 6800, 7800, 8800 Series, and Cisco Video Phone 8875 with Multiplatform Firmware.

4

What type of vulnerability is CVE-2024-20533?

CVE-2024-20533 is a stored cross-site scripting (XSS) vulnerability.

5

Can CVE-2024-20533 be exploited remotely?

Yes, CVE-2024-20533 can be exploited by an authenticated remote attacker.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203