Vulnslist

find the latest Cisco vulnerabilities

Cisco IP Phone 8800 Series Cross-Site Scripting Vulnerability

cisco-sa-20160810-ip-phone-8800 · Medium · Published · Updated

A vulnerability in the web application of the Cisco IP Phone 8800 Series could allow an authenticated, remote attacker to perform a stored, cross-site scripting (XSS) attack. The vulnerability is due to insufficient sanitization of parameter values. An attacker could exploit this vulnerability by storing malicious code on a device and waiting for a user to access a web page that triggers execution of the code. An exploit could allow the attacker to execute arbitrary script code in the context of the web interface on the affected device. Cisco has not released software updates that address this vulnerability. Workarounds that address this vulnerability are not available. This advisory is available at the following link: https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20160810-ip-phone-8800

Workarounds

Workarounds that address this vulnerability are not available.

CVEsCVE-2016-1476
Cisco Bug IDsCSCuz03024
CVSS ScoreBase 4.0
Base 4.0 AV:N/AC:L/Au:S/C:N/I:P/A:N/E:F/RL:U/RC:C
Product Names From Source
Cisco IP Phone 8800 Series Software

CSAF Product Statuses

Product Status Source CVE Rows
Cisco IP Phone 8800 Series Software known_affected cisco_csaf CVE-2016-1476 1

Related Products

Product CVE Evidence
Cisco IP phone CVE-2016-1476 Cisco OpenVuln
Cisco IP Phone 8800 Series Software CVE-2016-1476 Cisco CSAF
Cisco 8000 Series Routers CVE-2016-1476 Cisco OpenVuln