Vulnslist

find the latest Cisco vulnerabilities

Cisco IP Phones Call Log Information Disclosure Vulnerability

cisco-sa-phone-logs-2O7f7ExM · Medium · Published · Updated

A vulnerability in the Web Access feature of Cisco IP Phones could allow an unauthenticated, remote attacker to view sensitive information on an affected device. The vulnerability is due to improper access controls on the web-based management interface of an affected device. An attacker could exploit this vulnerability by sending malicious requests to the device, which could allow the attacker to bypass access restrictions. A successful attack could allow the attacker to view sensitive information, including device call logs that contain names, usernames, and phone numbers of users of the device. There are no workarounds that address this vulnerability. This advisory is available at the following link: https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-phone-logs-2O7f7ExM

Workarounds

There are no workarounds that address this vulnerability.

CVEsCVE-2020-3360
Cisco Bug IDsCSCvt23310, CSCvt27636, CSCvt27645, CSCvt27637
CVSS ScoreBase 5.3
Base 5.3 CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N/E:X/RL:X/RC:X
Product Names From Source
Cisco IP Phone 8800 Series Software, Cisco IP Phone 7800 Series

CSAF Product Statuses

Product Status Source CVE Rows
Cisco IP Phone 7800 Series known_affected cisco_csaf CVE-2020-3360 1
Cisco IP Phone 8800 Series Software known_affected cisco_csaf CVE-2020-3360 1

Related Products

Product CVE Evidence
Cisco IP phone CVE-2020-3360 Cisco OpenVuln
Cisco IP Phone 7800 Series CVE-2020-3360 Cisco CSAF
Cisco IP Phone 8800 Series Software CVE-2020-3360 Cisco CSAF
Cisco 8000 Series Routers CVE-2020-3360 Cisco OpenVuln