Vulnerability Description
A vulnerability in the web-based management interface of Cisco IP Phone firmware could allow an unauthenticated, remote attacker to cause an affected device to reload, resulting in a DoS condition. This vulnerability is due to insufficient validation of user-supplied input. An attacker could exploit this vulnerability by sending a crafted request to the web-based management interface of an affected device. A successful exploit could allow the attacker to cause the affected device to reload.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Cisco | Video Phone 8875 Firmware | < 2.3.1.0101 |
| Cisco | Video Phone 8875 | - |
| Cisco | Ip Phone 6821 With Multiplatform Firmware | <= 12.0.4 |
| Cisco | Ip Phone 6821 | - |
| Cisco | Ip Phone 6841 With Multiplatform Firmware | <= 12.0.4 |
| Cisco | Ip Phone 6841 | - |
| Cisco | Ip Phone 6851 With Multiplatform Firmware | <= 12.0.4 |
| Cisco | Ip Phone 6851 | - |
| Cisco | Ip Phone 6861 With Multiplatform Firmware | <= 12.0.4 |
| Cisco | Ip Phone 6861 | - |
| Cisco | Ip Phone 6871 With Multiplatform Firmware | <= 12.0.4 |
| Cisco | Ip Phone 6871 | - |
| Cisco | Ip Phone 7811 With Multiplatform Firmware | <= 12.0.4 |
| Cisco | Ip Phone 7811 | - |
| Cisco | Ip Phone 7821 With Multiplatform Firmware | <= 12.0.4 |
| Cisco | Ip Phone 7821 | - |
| Cisco | Ip Phone 7832 With Multiplatform Firmware | <= 12.0.4 |
| Cisco | Ip Phone 7832 | - |
| Cisco | Ip Phone 7841 With Multiplatform Firmware | <= 12.0.4 |
| Cisco | Ip Phone 7841 | - |
Related Weaknesses (CWE)
References
- https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/ciVendor Advisory
- https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/ciVendor Advisory
FAQ
What is CVE-2024-20376?
CVE-2024-20376 is a vulnerability with a CVSS score of 7.5 (HIGH). A vulnerability in the web-based management interface of Cisco IP Phone firmware could allow an unauthenticated, remote attacker to cause an affected device to reload, resulting in a DoS condition. ...
How severe is CVE-2024-20376?
CVE-2024-20376 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2024-20376?
Check the references section above for vendor advisories and patch information. Affected products include: Cisco Video Phone 8875 Firmware, Cisco Video Phone 8875, Cisco Ip Phone 6821 With Multiplatform Firmware, Cisco Ip Phone 6821, Cisco Ip Phone 6841 With Multiplatform Firmware.