CVE-2022-20774 is a Cross-Site Request Forgery (CSRF) vulnerability affecting the web-based management interface of Cisco IP Phone 6800, 7800, and 8800 Series with Multiplatform Firmware. With a CVSS score of 8.1 (High), an unauthenticated, remote attacker could exploit this by tricking an authenticated user into clicking a malicious link, leading to configuration changes and a denial of service. There is no evidence of active exploitation, public exploit code, or significant media coverage, though it has received some community discussion.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 11.3.5CPE matchmatch criteria | cpe:2.3:o:cisco:ip_phone_6871_firmware:*:*:*:*:*:*:*:* | ||
< 11.3.5CPE matchmatch criteria | cpe:2.3:o:cisco:ip_phone_6861_firmware:*:*:*:*:*:*:*:* | ||
< 11.3.5CPE matchmatch criteria | cpe:2.3:o:cisco:ip_phone_6851_firmware:*:*:*:*:*:*:*:* | ||
< 11.3.5CPE matchmatch criteria | cpe:2.3:o:cisco:ip_phone_6841_firmware:*:*:*:*:*:*:*:* | ||
< 11.3.5CPE matchmatch criteria | cpe:2.3:o:cisco:ip_phone_6825_firmware:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.