MEDIUM · 6.8

CVE-2022-20774

A vulnerability in the web-based management interface of Cisco IP Phone 6800, 7800, and 8800 Series with Multiplatform Firmware could allow an unauthenticated, remote attacker to conduct a cross-site ...

Vulnerability Description

A vulnerability in the web-based management interface of Cisco IP Phone 6800, 7800, and 8800 Series with Multiplatform Firmware could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack against a user of the web-based interface of an affected system. This vulnerability is due to insufficient CSRF protections for the web-based management interface of an affected device. An attacker could exploit this vulnerability by persuading an authenticated user of the interface to follow a crafted link. A successful exploit could allow the attacker to perform configuration changes on the affected device, resulting in a denial of service (DoS) condition.

CVSS Score

6.8

MEDIUM

CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:H/A:H
Attack Vector
NETWORK
Attack Complexity
HIGH
Privileges Required
NONE
User Interaction
REQUIRED
Scope
UNCHANGED
Confidentiality
NONE
Integrity
HIGH
Availability
HIGH

Affected Products

VendorProductVersions
CiscoIp Phone 6871 Firmware< 11.3.5
CiscoIp Phone 6871-
CiscoIp Phone 6861 Firmware< 11.3.5
CiscoIp Phone 6861-
CiscoIp Phone 6851 Firmware< 11.3.5
CiscoIp Phone 6851-
CiscoIp Phone 6841 Firmware< 11.3.5
CiscoIp Phone 6841-
CiscoIp Phone 6825 Firmware< 11.3.5
CiscoIp Phone 6825-
CiscoIp Phone 7861 Firmware< 11.3.5
CiscoIp Phone 7861-
CiscoIp Phone 7841 Firmware< 11.3.5
CiscoIp Phone 7841-
CiscoIp Phone 7832 Firmware< 11.3.5
CiscoIp Phone 7832-
CiscoIp Phone 7821 Firmware< 11.3.5
CiscoIp Phone 7821-
CiscoIp Phone 7811 Firmware< 11.3.5
CiscoIp Phone 7811-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2022-20774?

CVE-2022-20774 is a vulnerability with a CVSS score of 6.8 (MEDIUM). A vulnerability in the web-based management interface of Cisco IP Phone 6800, 7800, and 8800 Series with Multiplatform Firmware could allow an unauthenticated, remote attacker to conduct a cross-site ...

How severe is CVE-2022-20774?

CVE-2022-20774 has been rated MEDIUM with a CVSS base score of 6.8/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2022-20774?

Check the references section above for vendor advisories and patch information. Affected products include: Cisco Ip Phone 6871 Firmware, Cisco Ip Phone 6871, Cisco Ip Phone 6861 Firmware, Cisco Ip Phone 6861, Cisco Ip Phone 6851 Firmware.