Vulnslist

find the latest Cisco vulnerabilities

CVE-2020-3360

A vulnerability in the Web Access feature of Cisco IP Phones Series 7800 and Series 8800 could allow an unauthenticated, remote attacker to view sensitive information on an affected device. The vulnerability is due to improper access controls on the web-based management interface of an affected device. An attacker could exploit this vulnerability by sending malicious requests to the device, which could allow the attacker to bypass access restrictions. A successful attack could allow the attacker to view sensitive information, including device call logs that contain names, usernames, and phone numbers of users of the device.

SeverityMEDIUM
CVSS5.3
EPSS0.36%
CWECWE-200
KEV
Published
Modified

CSAF Product Statuses

Product Status Source Advisory Rows
Cisco IP Phone 7800 Series known_affected cisco_csaf cisco-sa-phone-logs-2O7f7ExM 1
Cisco IP Phone 8800 Series Software known_affected cisco_csaf cisco-sa-phone-logs-2O7f7ExM 1

Related Products

Product Advisory
Cisco IP phone cisco-sa-phone-logs-2O7f7ExM
Cisco IP Phone 7800 Series cisco-sa-phone-logs-2O7f7ExM
Cisco IP Phone 8800 Series Software cisco-sa-phone-logs-2O7f7ExM
Cisco 8000 Series Routers cisco-sa-phone-logs-2O7f7ExM