cve/2024/CVE-2024-20445.md

89 lines
7.7 KiB
Markdown
Raw Normal View History

2025-09-29 21:09:30 +02:00
### [CVE-2024-20445](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-20445)
![](https://img.shields.io/static/v1?label=Product&message=Cisco%20Session%20Initiation%20Protocol%20(SIP)%20Software&color=blue)
![](https://img.shields.io/static/v1?label=Version&message=10.1(1)SR1%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=10.1(1)SR2%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=10.1(1.9)%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=10.2(1)%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=10.2(1)SR1%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=10.2(2)%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=10.3(1)%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=10.3(1)SR1%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=10.3(1)SR2%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=10.3(1)SR3%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=10.3(1)SR4%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=10.3(1)SR4b%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=10.3(1)SR5%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=10.3(1)SR6%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=10.3(1)SR7%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=10.3(1.11)%203rd%20Party%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=10.3(1.11)_3rd_Party%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=10.3(1.9)%203rd%20Party%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=10.3(1.9)_3rd_Party%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=10.3(2)%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=10.4(1)%203rd%20Party%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=10.4(1)SR2%203rd%20Party%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=10.4(1)SR2_3rd_Party%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=10.4(1)_3rd_Party%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=11-0-1MSR1-1%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=11.0(0.7)%20MPP%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=11.0(0.7)_MPP%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=11.0(1)%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=11.5(1)%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=11.5(1)SR1%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=11.7(1)%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=12.0(1)%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=12.0(1)SR1%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=12.0(1)SR2%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=12.0(1)SR3%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=12.1(1)%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=12.1(1)SR1%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=12.5(1)%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=12.5(1)SR1%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=12.5(1)SR2%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=12.5(1)SR3%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=12.6(1)%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=12.6(1)SR1%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=12.7(1)%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=12.7(1)SR1%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=12.8(1)%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=12.8(1)SR1%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=12.8(1)SR2%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=14.0(1)%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=14.0(1)SR1%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=14.0(1)SR2%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=14.0(1)SR3%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=14.1(1)%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=14.1(1)SR1%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=14.1(1)SR2%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=14.1(1)SR3%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=14.2(1)%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=14.2(1)SR1%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=14.2(1)SR2%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=14.2(1)SR3%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=3.0(1)%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=3.1(1)%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=3.1(1)SR1%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=9.3(3)%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=9.3(4)%203rd%20Party%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=9.3(4)SR1%203rd%20Party%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=9.3(4)SR1_3rd_Party%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=9.3(4)SR2%203rd%20Party%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=9.3(4)SR2_3rd_Party%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=9.3(4)SR3%203rd%20Party%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=9.3(4)SR3_3rd_Party%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=9.3(4)_3rd_Party%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Vulnerability&message=Exposure%20of%20Sensitive%20Information%20to%20an%20Unauthorized%20Actor&color=brightgreen)
### Description
A vulnerability in the web UI of Cisco Desk Phone 9800 Series, Cisco IP Phone 7800 and 8800 Series, and Cisco Video Phone 8875 could allow an unauthenticated, remote attacker to access sensitive information on an affected device. This vulnerability is due to improper storage of sensitive information within the web UI of Session Initiation Protocol (SIP)-based phone loads. An attacker could exploit this vulnerability by browsing to the IP address of a device that has Web Access enabled. A successful exploit could allow the attacker to access sensitive information, including incoming and outgoing call records. Note: Web Access is disabled by default.
### POC
#### Reference
No PoCs from references.
#### Github
- https://github.com/fkie-cad/nvd-json-data-feeds