CVE-2023-20079 describes multiple vulnerabilities in the web-based management interface of certain Cisco IP Phones, potentially allowing an unauthenticated, remote attacker to execute arbitrary code or cause a denial of service. This vulnerability carries a high CVSS score of 7.5, indicating a critical risk due to its network-based attack vector and low attack complexity, with the primary impact being denial of service. While there is no evidence of active exploitation (KEV: No), the vulnerability has garnered significant community attention with 13 mentions and 3 media articles, including reports of a critical Web UI RCE flaw. Despite this, no public exploit code (Metasploit, Nuclei, ExploitDB) is currently available.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 11.3.7sr1CPE matchmatch criteria | cpe:2.3:o:cisco:ip_phone_6871_firmware:*:*:*:*:*:*:*:* | ||
< 11.3.7sr1CPE matchmatch criteria | cpe:2.3:o:cisco:ip_phone_6861_firmware:*:*:*:*:*:*:*:* | ||
< 11.3.7sr1CPE matchmatch criteria | cpe:2.3:o:cisco:ip_phone_6851_firmware:*:*:*:*:*:*:*:* | ||
< 11.3.7sr1CPE matchmatch criteria | cpe:2.3:o:cisco:ip_phone_6841_firmware:*:*:*:*:*:*:*:* | ||
< 11.3.7sr1CPE matchmatch criteria | cpe:2.3:o:cisco:ip_phone_6825_firmware:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.