MEDIUM · 6.5

CVE-2023-20221

A vulnerability in the web-based management interface of Cisco IP Phone 6800, 7800, and 8800 Series with Multiplatform Firmware could allow an unauthenticated, remote attacker to conduct a cross-site ...

Vulnerability Description

A vulnerability in the web-based management interface of Cisco IP Phone 6800, 7800, and 8800 Series with Multiplatform Firmware could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack against a user of the web-based management interface of an affected system. This vulnerability is due to insufficient CSRF protections for the web-based management interface of an affected device. An attacker could exploit this vulnerability by persuading an authenticated user of the interface to follow a crafted link. A successful exploit could allow the attacker to perform a factory reset of the affected device, resulting in a Denial of Service (DoS) condition.

CVSS Score

6.5

MEDIUM

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
REQUIRED
Scope
UNCHANGED
Confidentiality
NONE
Integrity
NONE
Availability
HIGH

Affected Products

VendorProductVersions
CiscoVideo Phone 8875 Firmware< 2.0
CiscoVideo Phone 8875-
CiscoIp Phone 6821 With Multiplatform Firmware11-3-1mppsr4upg
CiscoIp Phone 6821-
CiscoIp Phone 6825 With Multiplatform Firmware11-3-1mppsr4upg
CiscoIp Phone 6825-
CiscoIp Phone 6841 With Multiplatform Firmware11-3-1mppsr4upg
CiscoIp Phone 6841-
CiscoIp Phone 6851 With Multiplatform Firmware11-3-1mppsr4upg
CiscoIp Phone 6851-
CiscoIp Phone 6861 With Multiplatform Firmware11-3-1mppsr4upg
CiscoIp Phone 6861-
CiscoIp Phone 6871 With Multiplatform Firmware11-3-1mppsr4upg
CiscoIp Phone 6871-
CiscoIp Conference Phone 7832 With Multiplatform Firmware11-3-1mppsr4upg
CiscoIp Conference Phone 7832-
CiscoIp Phone 7811 With Multiplatform Firmware11-3-1mppsr4upg
CiscoIp Phone 7811-
CiscoIp Phone 7821 With Multiplatform Firmware11-3-1mppsr4upg
CiscoIp Phone 7821-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2023-20221?

CVE-2023-20221 is a vulnerability with a CVSS score of 6.5 (MEDIUM). A vulnerability in the web-based management interface of Cisco IP Phone 6800, 7800, and 8800 Series with Multiplatform Firmware could allow an unauthenticated, remote attacker to conduct a cross-site ...

How severe is CVE-2023-20221?

CVE-2023-20221 has been rated MEDIUM with a CVSS base score of 6.5/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2023-20221?

Check the references section above for vendor advisories and patch information. Affected products include: Cisco Video Phone 8875 Firmware, Cisco Video Phone 8875, Cisco Ip Phone 6821 With Multiplatform Firmware, Cisco Ip Phone 6821, Cisco Ip Phone 6825 With Multiplatform Firmware.