cisco-sa-20190320-ipab: Cisco IP Phone 8800 Series Authorization Bypass Vulnerability
A vulnerability in the web-based management interface of Session Initiation Protocol (SIP) Software for Cisco IP Phone 8800 Series could allow an unauthenticated, remote attacker to bypass authorization, access critical services, and cause a denial of service (DoS) condition. The vulnerability exists because the software fails to sanitize URLs before it handles requests. An attacker could exploit this vulnerability by submitting a crafted URL. A successful exploit could allow the attacker to gain unauthorized access to critical services and cause a DoS condition. Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability.
This advisory is available at the following link: https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20190320-ipab
Credit
Affected Software
Event History
Frequently Asked Questions
What is the severity of cisco-sa-20190320-ipab?
The severity of cisco-sa-20190320-ipab is high due to the potential for unauthenticated remote access and denial of service.
How do I fix cisco-sa-20190320-ipab?
To fix cisco-sa-20190320-ipab, update your Cisco IP Phone 8800 Series to the latest software version recommended by Cisco.
What systems are affected by cisco-sa-20190320-ipab?
Cisco IP Phone 8800 Series devices are affected by the cisco-sa-20190320-ipab vulnerability.
Is authentication required to exploit cisco-sa-20190320-ipab?
No, authentication is not required to exploit the cisco-sa-20190320-ipab vulnerability.
What could an attacker achieve by exploiting cisco-sa-20190320-ipab?
An attacker could bypass authorization and access critical services or cause a denial of service in devices affected by cisco-sa-20190320-ipab.