2023-04-24 12:24:31 +02:00
{
"id" : "CVE-2023-20079" ,
"sourceIdentifier" : "ykramarz@cisco.com" ,
"published" : "2023-03-03T16:15:10.380" ,
2023-11-07 21:03:21 +00:00
"lastModified" : "2023-11-07T04:05:58.637" ,
"vulnStatus" : "Modified" ,
2024-07-14 02:06:08 +00:00
"cveTags" : [ ] ,
2023-04-24 12:24:31 +02:00
"descriptions" : [
{
"lang" : "en" ,
"value" : "Multiple vulnerabilities in the web-based management interface of certain Cisco IP Phones could allow an unauthenticated, remote attacker to execute arbitrary code or cause a denial of service (DoS) condition. For more information about these vulnerabilities, see the Details section of this advisory."
}
] ,
"metrics" : {
"cvssMetricV31" : [
{
"source" : "nvd@nist.gov" ,
"type" : "Primary" ,
"cvssData" : {
"version" : "3.1" ,
"vectorString" : "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" ,
"attackVector" : "NETWORK" ,
"attackComplexity" : "LOW" ,
"privilegesRequired" : "NONE" ,
"userInteraction" : "NONE" ,
"scope" : "UNCHANGED" ,
"confidentialityImpact" : "NONE" ,
"integrityImpact" : "NONE" ,
"availabilityImpact" : "HIGH" ,
"baseScore" : 7.5 ,
"baseSeverity" : "HIGH"
} ,
"exploitabilityScore" : 3.9 ,
"impactScore" : 3.6
2023-11-07 21:03:21 +00:00
} ,
2023-04-24 12:24:31 +02:00
{
2024-04-04 08:46:00 +00:00
"source" : "ykramarz@cisco.com" ,
2023-04-24 12:24:31 +02:00
"type" : "Secondary" ,
"cvssData" : {
2023-11-07 21:03:21 +00:00
"version" : "3.1" ,
"vectorString" : "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" ,
2023-04-24 12:24:31 +02:00
"attackVector" : "NETWORK" ,
"attackComplexity" : "LOW" ,
"privilegesRequired" : "NONE" ,
"userInteraction" : "NONE" ,
"scope" : "UNCHANGED" ,
"confidentialityImpact" : "HIGH" ,
"integrityImpact" : "HIGH" ,
"availabilityImpact" : "HIGH" ,
"baseScore" : 9.8 ,
"baseSeverity" : "CRITICAL"
} ,
"exploitabilityScore" : 3.9 ,
"impactScore" : 5.9
}
]
} ,
"weaknesses" : [
{
"source" : "nvd@nist.gov" ,
"type" : "Primary" ,
"description" : [
{
"lang" : "en" ,
"value" : "CWE-787"
}
]
} ,
{
2024-04-04 08:46:00 +00:00
"source" : "ykramarz@cisco.com" ,
2023-04-24 12:24:31 +02:00
"type" : "Secondary" ,
"description" : [
{
"lang" : "en" ,
"value" : "CWE-121"
}
]
}
] ,
"configurations" : [
{
"operator" : "AND" ,
"nodes" : [
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:o:cisco:ip_phone_6871_firmware:*:*:*:*:*:*:*:*" ,
"versionEndExcluding" : "11.3.7sr1" ,
"matchCriteriaId" : "7FB46C93-0E51-42F3-8F94-40042A5CBF46"
}
]
} ,
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : false ,
"criteria" : "cpe:2.3:h:cisco:ip_phone_6871:-:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "864B486C-71F6-4EFD-8F04-BA7FC18DFD5B"
}
]
}
]
} ,
{
"operator" : "AND" ,
"nodes" : [
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:o:cisco:ip_phone_6861_firmware:*:*:*:*:*:*:*:*" ,
"versionEndExcluding" : "11.3.7sr1" ,
"matchCriteriaId" : "4AD2F635-094B-4883-BF55-B85B16AD773F"
}
]
} ,
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : false ,
"criteria" : "cpe:2.3:h:cisco:ip_phone_6861:-:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "C05A7CA6-AD58-45D7-AF32-129E22855D8E"
}
]
}
]
} ,
{
"operator" : "AND" ,
"nodes" : [
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:o:cisco:ip_phone_6851_firmware:*:*:*:*:*:*:*:*" ,
"versionEndExcluding" : "11.3.7sr1" ,
"matchCriteriaId" : "39BA7B78-4934-404F-B4DF-6C936460E05E"
}
]
} ,
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : false ,
"criteria" : "cpe:2.3:h:cisco:ip_phone_6851:-:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "5809CA01-CF32-4E3A-A771-01D5065F0061"
}
]
}
]
} ,
{
"operator" : "AND" ,
"nodes" : [
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:o:cisco:ip_phone_6841_firmware:*:*:*:*:*:*:*:*" ,
"versionEndExcluding" : "11.3.7sr1" ,
"matchCriteriaId" : "470A77FC-6DD6-44B8-B332-79844AE06BB2"
}
]
} ,
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : false ,
"criteria" : "cpe:2.3:h:cisco:ip_phone_6841:-:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "CE4960B1-22B4-4B3D-955E-684DA520A1A5"
}
]
}
]
} ,
{
"operator" : "AND" ,
"nodes" : [
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:o:cisco:ip_phone_6825_firmware:*:*:*:*:*:*:*:*" ,
"versionEndExcluding" : "11.3.7sr1" ,
"matchCriteriaId" : "3CB8846B-6B42-49AF-BFC9-85CF89CA4E56"
}
]
} ,
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : false ,
"criteria" : "cpe:2.3:h:cisco:ip_phone_6825:-:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "E07D81AF-3DF8-4EE4-AE4E-FB875BE14BB4"
}
]
}
]
} ,
{
"operator" : "AND" ,
"nodes" : [
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:o:cisco:ip_phone_7861_firmware:*:*:*:*:*:*:*:*" ,
"versionEndExcluding" : "11.3.7sr1" ,
"matchCriteriaId" : "6F675EDC-3F39-4BDA-B6BD-2A0C1075D1D8"
}
]
} ,
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : false ,
"criteria" : "cpe:2.3:h:cisco:ip_phone_7861:-:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "E52C420C-FD54-4BE4-8720-E05307D53520"
}
]
}
]
} ,
{
"operator" : "AND" ,
"nodes" : [
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:o:cisco:ip_phone_7841_firmware:*:*:*:*:*:*:*:*" ,
"versionEndExcluding" : "11.3.7sr1" ,
"matchCriteriaId" : "3D9466BE-960D-41DD-A137-ABE2C3F6D4B4"
}
]
} ,
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : false ,
"criteria" : "cpe:2.3:h:cisco:ip_phone_7841:-:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "73CF8A50-11BD-4506-BF2A-CCA36BF59EFF"
}
]
}
]
} ,
{
"operator" : "AND" ,
"nodes" : [
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:o:cisco:ip_phone_7832_firmware:*:*:*:*:*:*:*:*" ,
"versionEndExcluding" : "11.3.7sr1" ,
"matchCriteriaId" : "D27EA4CE-9BA5-42B8-B1CE-5710A6207CC2"
}
]
} ,
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : false ,
"criteria" : "cpe:2.3:h:cisco:ip_phone_7832:-:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "32D8B3FD-3157-49D3-A4BA-D4FAAB1B6D4C"
}
]
}
]
} ,
{
"operator" : "AND" ,
"nodes" : [
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:o:cisco:ip_phone_7821_firmware:*:*:*:*:*:*:*:*" ,
"versionEndExcluding" : "11.3.7sr1" ,
"matchCriteriaId" : "4550A390-A8D8-4857-8C66-EC6B1F8E322E"
}
]
} ,
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : false ,
"criteria" : "cpe:2.3:h:cisco:ip_phone_7821:-:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "AE7AFFF0-5B21-400B-B923-E9B7FCCE08FA"
}
]
}
]
} ,
{
"operator" : "AND" ,
"nodes" : [
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:o:cisco:ip_phone_7811_firmware:*:*:*:*:*:*:*:*" ,
"versionEndExcluding" : "11.3.7sr1" ,
"matchCriteriaId" : "D975C4C2-9567-4F5C-BE6A-137AE321F9F0"
}
]
} ,
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : false ,
"criteria" : "cpe:2.3:h:cisco:ip_phone_7811:-:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "D7260C17-7067-47AD-995F-366A5E8B10E7"
}
]
}
]
} ,
{
"operator" : "AND" ,
"nodes" : [
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:o:cisco:ip_phone_8865_firmware:*:*:*:*:*:*:*:*" ,
"versionEndExcluding" : "11.3.7sr1" ,
"matchCriteriaId" : "E8BD1967-D870-4E21-BF1C-D712809077EB"
}
]
} ,
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : false ,
"criteria" : "cpe:2.3:h:cisco:ip_phone_8865:-:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "BB99B9AB-64B5-4989-9579-A1BB5D2D87EF"
}
]
}
]
} ,
{
"operator" : "AND" ,
"nodes" : [
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:o:cisco:ip_phone_8861_firmware:*:*:*:*:*:*:*:*" ,
"versionEndExcluding" : "11.3.7sr1" ,
"matchCriteriaId" : "ACB956C5-4165-4C00-BC5C-F4D4C6270070"
}
]
} ,
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : false ,
"criteria" : "cpe:2.3:h:cisco:ip_phone_8861:-:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "090EE553-01D5-45F0-87A4-E1167F46EB77"
}
]
}
]
} ,
{
"operator" : "AND" ,
"nodes" : [
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:o:cisco:ip_phone_8851_firmware:*:*:*:*:*:*:*:*" ,
"versionEndExcluding" : "11.3.7sr1" ,
"matchCriteriaId" : "83E1D601-371E-4F90-B6F7-8A6B91C949AB"
}
]
} ,
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : false ,
"criteria" : "cpe:2.3:h:cisco:ip_phone_8851:-:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "8AF6DC5E-F582-445E-BF05-2D55A0954663"
}
]
}
]
} ,
{
"operator" : "AND" ,
"nodes" : [
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:o:cisco:ip_phone_8845_firmware:*:*:*:*:*:*:*:*" ,
"versionEndExcluding" : "11.3.7sr1" ,
"matchCriteriaId" : "7C4C70C3-D9D7-468C-B522-666EF6C01D20"
}
]
} ,
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : false ,
"criteria" : "cpe:2.3:h:cisco:ip_phone_8845:-:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "A313E64A-F43C-4FBA-A389-6171CBD709C0"
}
]
}
]
} ,
{
"operator" : "AND" ,
"nodes" : [
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:o:cisco:ip_phone_8841_firmware:*:*:*:*:*:*:*:*" ,
"versionEndExcluding" : "11.3.7sr1" ,
"matchCriteriaId" : "C7609CA0-F9E8-47AB-A621-212DC124018E"
}
]
} ,
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : false ,
"criteria" : "cpe:2.3:h:cisco:ip_phone_8841:-:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "7944CC9C-AE08-4F30-AF65-134DADBD0FA1"
}
]
}
]
} ,
{
"operator" : "AND" ,
"nodes" : [
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:o:cisco:ip_phone_8832_firmware:*:*:*:*:*:*:*:*" ,
"versionEndExcluding" : "11.3.7sr1" ,
"matchCriteriaId" : "5D936075-78C7-4E1E-A2B1-1EB8B668E3F2"
}
]
} ,
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : false ,
"criteria" : "cpe:2.3:h:cisco:ip_phone_8832:-:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "A5EA5C6B-243B-419A-9C60-1CDBD039C1D8"
}
]
}
]
} ,
{
"operator" : "AND" ,
"nodes" : [
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:o:cisco:ip_phone_8811_firmware:*:*:*:*:*:*:*:*" ,
"versionEndExcluding" : "11.3.7sr1" ,
"matchCriteriaId" : "2691AABE-6E0A-422B-88B9-89E63D1436F3"
}
]
} ,
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : false ,
"criteria" : "cpe:2.3:h:cisco:ip_phone_8811:-:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "D0CC3127-3152-4906-9FE0-BC6F21DCADAA"
}
]
}
]
} ,
{
"operator" : "AND" ,
"nodes" : [
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:o:cisco:ip_phone_8831_firmware:*:*:*:*:*:*:*:*" ,
"versionEndExcluding" : "11.3.7sr1" ,
"matchCriteriaId" : "6579DD70-1AC9-42FC-9464-90523A7008E7"
}
]
} ,
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : false ,
"criteria" : "cpe:2.3:h:cisco:ip_phone_8831:-:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "CF13D70B-1F27-4B3F-83FD-EF9688F1D123"
}
]
}
]
} ,
{
"operator" : "AND" ,
"nodes" : [
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:o:cisco:unified_ip_phone_7945g_firmware:*:*:*:*:*:*:*:*" ,
"versionEndExcluding" : "11.3.7sr1" ,
"matchCriteriaId" : "E49D5D04-A5B9-461D-94A3-15676DD90CD6"
}
]
} ,
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : false ,
"criteria" : "cpe:2.3:h:cisco:unified_ip_phone_7945g:-:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "5980E646-CA07-4222-A9DD-A71306A4A678"
}
]
}
]
} ,
{
"operator" : "AND" ,
"nodes" : [
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:o:cisco:unified_ip_phone_7965g_firmware:*:*:*:*:*:*:*:*" ,
"versionEndExcluding" : "11.3.7sr1" ,
"matchCriteriaId" : "0587084E-0B87-46D3-A5D8-3FD7EBC826E1"
}
]
} ,
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : false ,
"criteria" : "cpe:2.3:h:cisco:unified_ip_phone_7965g:-:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "FF30D1CC-D27F-49FF-9C63-BB890002D1C2"
}
]
}
]
} ,
{
"operator" : "AND" ,
"nodes" : [
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:o:cisco:unified_ip_phone_7975g_firmware:*:*:*:*:*:*:*:*" ,
"versionEndExcluding" : "11.3.7sr1" ,
"matchCriteriaId" : "C77D2870-D2C9-40D7-8877-F9E9AD4E1DF8"
}
]
} ,
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : false ,
"criteria" : "cpe:2.3:h:cisco:unified_ip_phone_7975g:-:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "8BA879B6-04D6-402A-8F38-8A7CB34D76F4"
}
]
}
]
}
] ,
"references" : [
{
"url" : "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ip-phone-cmd-inj-KMFynVcP" ,
"source" : "ykramarz@cisco.com" ,
"tags" : [
"Vendor Advisory"
]
}
]
}