cisco-sa-ip-phone-info-disc-fRdJfOxA: Cisco IP Phones Information Disclosure Vulnerability
A vulnerability in the information storage architecture of several Cisco IP Phone models could allow an unauthenticated, physical attacker to obtain confidential information from an affected device. This vulnerability is due to unencrypted storage of confidential information on an affected device. An attacker could exploit this vulnerability by physically extracting and accessing one of the flash memory chips. A successful exploit could allow the attacker to obtain confidential information from the device, which could be used for subsequent attacks. Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability. This advisory is available at the following link:https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ip-phone-info-disc-fRdJfOxA
Credit
Affected Software
Event History
Frequently Asked Questions
What is the severity of cisco-sa-ip-phone-info-disc-fRdJfOxA?
The severity of cisco-sa-ip-phone-info-disc-fRdJfOxA is classified as high due to the potential for unauthorized access to confidential information.
How do I fix cisco-sa-ip-phone-info-disc-fRdJfOxA?
To fix cisco-sa-ip-phone-info-disc-fRdJfOxA, ensure that all affected Cisco IP Phones are updated to the latest firmware that addresses this vulnerability.
Which products are affected by cisco-sa-ip-phone-info-disc-fRdJfOxA?
Affected products include Wireless IP Phones 8821, Unified SIP Phone 3905, Unified IP Phones 7945G, 7965G, 7975G, and several others listed by Cisco.
Can cisco-sa-ip-phone-info-disc-fRdJfOxA be exploited remotely?
No, cisco-sa-ip-phone-info-disc-fRdJfOxA requires physical access to the device for exploitation.
What information can be exposed due to cisco-sa-ip-phone-info-disc-fRdJfOxA?
The vulnerability can expose confidential information stored unencrypted on affected Cisco IP Phone models.