imPC@ndo IT

Tracker / CVE-2023-20078

CVE-2023-20078

Critical 9.8

Multiple vulnerabilities in the web-based management interface of certain Cisco IP Phones could allow an unauthenticated, remote attacker to execute arbitrary code or cause a denial of service (DoS) condition. For more information about these vulnerabilities, see the Details section of this advisory.

Affected products and versions

cisco ip_phone_6825_firmware · … → 11.3.7sr1
cisco ip_phone_6841_firmware · … → 11.3.7sr1
cisco ip_phone_6851_firmware · … → 11.3.7sr1
cisco ip_phone_6861_firmware · … → 11.3.7sr1
cisco ip_phone_6871_firmware · … → 11.3.7sr1
cisco ip_phone_7811_firmware · … → 11.3.7sr1
cisco ip_phone_7821_firmware · … → 11.3.7sr1
cisco ip_phone_7832_firmware · … → 11.3.7sr1
cisco ip_phone_7841_firmware · … → 11.3.7sr1
cisco ip_phone_7861_firmware · … → 11.3.7sr1
cisco ip_phone_8811_firmware · … → 11.3.7sr1
cisco ip_phone_8832_firmware · … → 11.3.7sr1
cisco ip_phone_8841_firmware · … → 11.3.7sr1
cisco ip_phone_8845_firmware · … → 11.3.7sr1
cisco ip_phone_8851_firmware · … → 11.3.7sr1
cisco ip_phone_8861_firmware · … → 11.3.7sr1
cisco ip_phone_8865_firmware · … → 11.3.7sr1

Analysis

This page is not indexable yet.Until it carries original analysis — what it actually exposes, how to check in two minutes whether a system was touched, what to do if it was — the page stays noindex. The database decides that, not the template.

References