Vulnerability Description
A vulnerability in Cisco Unified IP Phones could allow an unauthenticated, remote attacker to impersonate another user's phone if the Cisco Unified Communications Manager (CUCM) is in secure mode. This vulnerability is due to improper key generation during the manufacturing process that could result in duplicated manufactured keys installed on multiple devices. An attacker could exploit this vulnerability by performing a machine-in-the-middle attack on the secure communication between the phone and the CUCM. A successful exploit could allow the attacker to impersonate another user's phone. This vulnerability cannot be addressed with software updates. There is a workaround that addresses this vulnerability.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Cisco | Unified Ip Phone 6911 Firmware | - |
| Cisco | Unified Ip Phone 6911 | - |
| Cisco | Unified Ip Phone 6921 Firmware | - |
| Cisco | Unified Ip Phone 6921 | - |
| Cisco | Unified Ip Phone 6941 Firmware | - |
| Cisco | Unified Ip Phone 6941 | - |
| Cisco | Unified Ip Phone 6945 Firmware | - |
| Cisco | Unified Ip Phone 6945 | - |
| Cisco | Unified Ip Phone 6961 Firmware | - |
| Cisco | Unified Ip Phone 6961 | - |
| Cisco | Unified Ip Phone 8941 Firmware | - |
| Cisco | Unified Ip Phone 8941 | - |
| Cisco | Unified Ip Phone 8945 Firmware | - |
| Cisco | Unified Ip Phone 8945 | - |
| Cisco | Unified Ip Phone 8961 Firmware | - |
| Cisco | Unified Ip Phone 8961 | - |
| Cisco | Unified Ip Phone 9951 Firmware | - |
| Cisco | Unified Ip Phone 9951 | - |
| Cisco | Unified Ip Phone 9971 Firmware | - |
| Cisco | Unified Ip Phone 9971 | - |
Related Weaknesses (CWE)
References
- https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-cVendor Advisory
- https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-cVendor Advisory
FAQ
What is CVE-2022-20817?
CVE-2022-20817 is a vulnerability with a CVSS score of 7.4 (HIGH). A vulnerability in Cisco Unified IP Phones could allow an unauthenticated, remote attacker to impersonate another user's phone if the Cisco Unified Communications Manager (CUCM) is in secure mode. Thi...
How severe is CVE-2022-20817?
CVE-2022-20817 has been rated HIGH with a CVSS base score of 7.4/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2022-20817?
Check the references section above for vendor advisories and patch information. Affected products include: Cisco Unified Ip Phone 6911 Firmware, Cisco Unified Ip Phone 6911, Cisco Unified Ip Phone 6921 Firmware, Cisco Unified Ip Phone 6921, Cisco Unified Ip Phone 6941 Firmware.