Vulnerability Description
A vulnerability in the web-based management interface of Cisco IP Phone 6800, 7800, and 8800 Series with Multiplatform Firmware could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack against a user of the web-based management interface of an affected system. This vulnerability is due to insufficient CSRF protections for the web-based management interface of an affected device. An attacker could exploit this vulnerability by persuading an authenticated user of the interface to follow a crafted link. A successful exploit could allow the attacker to perform a factory reset of the affected device, resulting in a Denial of Service (DoS) condition.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Cisco | Video Phone 8875 Firmware | < 2.0 |
| Cisco | Video Phone 8875 | - |
| Cisco | Ip Phone 6821 With Multiplatform Firmware | 11-3-1mppsr4upg |
| Cisco | Ip Phone 6821 | - |
| Cisco | Ip Phone 6825 With Multiplatform Firmware | 11-3-1mppsr4upg |
| Cisco | Ip Phone 6825 | - |
| Cisco | Ip Phone 6841 With Multiplatform Firmware | 11-3-1mppsr4upg |
| Cisco | Ip Phone 6841 | - |
| Cisco | Ip Phone 6851 With Multiplatform Firmware | 11-3-1mppsr4upg |
| Cisco | Ip Phone 6851 | - |
| Cisco | Ip Phone 6861 With Multiplatform Firmware | 11-3-1mppsr4upg |
| Cisco | Ip Phone 6861 | - |
| Cisco | Ip Phone 6871 With Multiplatform Firmware | 11-3-1mppsr4upg |
| Cisco | Ip Phone 6871 | - |
| Cisco | Ip Conference Phone 7832 With Multiplatform Firmware | 11-3-1mppsr4upg |
| Cisco | Ip Conference Phone 7832 | - |
| Cisco | Ip Phone 7811 With Multiplatform Firmware | 11-3-1mppsr4upg |
| Cisco | Ip Phone 7811 | - |
| Cisco | Ip Phone 7821 With Multiplatform Firmware | 11-3-1mppsr4upg |
| Cisco | Ip Phone 7821 | - |
Related Weaknesses (CWE)
References
- https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/ciVendor Advisory
- https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/ciVendor Advisory
FAQ
What is CVE-2023-20221?
CVE-2023-20221 is a vulnerability with a CVSS score of 6.5 (MEDIUM). A vulnerability in the web-based management interface of Cisco IP Phone 6800, 7800, and 8800 Series with Multiplatform Firmware could allow an unauthenticated, remote attacker to conduct a cross-site ...
How severe is CVE-2023-20221?
CVE-2023-20221 has been rated MEDIUM with a CVSS base score of 6.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2023-20221?
Check the references section above for vendor advisories and patch information. Affected products include: Cisco Video Phone 8875 Firmware, Cisco Video Phone 8875, Cisco Ip Phone 6821 With Multiplatform Firmware, Cisco Ip Phone 6821, Cisco Ip Phone 6825 With Multiplatform Firmware.