CVE-2020-3360 describes an improper access control vulnerability in the Web Access feature of Cisco IP Phones Series 7800 and 8800. An unauthenticated, remote attacker can exploit this to bypass access restrictions and view sensitive information, such as call logs containing user names and phone numbers. This vulnerability has a CVSS score of 5.3 (Medium), indicating a low impact on confidentiality with no integrity or availability impact. There is currently no public exploit code available (Metasploit, Nuclei, ExploitDB), and it is not listed on the KEV catalog, suggesting no active exploitation. Community discussion and media coverage for this CVE are minimal.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 12.8\(1\)CPE matchmatch criteria | cpe:2.3:o:cisco:unified_ip_phone_6901_firmware:*:*:*:*:*:*:*:* | ||
<= 12.8\(1\)CPE matchmatch criteria | cpe:2.3:o:cisco:unified_ip_phone_6961_firmware:*:*:*:*:*:*:*:* | ||
<= 12.8\(1\)CPE matchmatch criteria | cpe:2.3:o:cisco:unified_ip_phone_6945_firmware:*:*:*:*:*:*:*:* | ||
<= 12.8\(1\)CPE matchmatch criteria | cpe:2.3:o:cisco:unified_ip_phone_6941_firmware:*:*:*:*:*:*:*:* | ||
<= 12.8\(1\)CPE matchmatch criteria | cpe:2.3:o:cisco:unified_ip_phone_6921_firmware:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.