Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

fstec логотип

BDU:2026-01766

Опубликовано: 03 сент. 2025
Источник: fstec
CVSS3: 5.3
CVSS2: 5
EPSS Низкий

Описание

Уязвимость микропрограммного обеспечения Cisco SIP IP-телефонов Cisco Video Phone 8875, Desk Phone 9800 и IP Phone 7800, 8800 Series связана с раскрытием информации. Эксплуатация уязвимости может позволить нарушителю, действующему удаленно, получить несанкционированный доступ к конфиденциальной информации

Вендор

Cisco Systems Inc.

Наименование ПО

Video Phone 8875
Cisco Desk Phone 9800
Cisco IP Phone 7800
Cisco IP Phone 8800
Cisco IP Phone 8821

Версия ПО

до 2.3(1)SR1 включительно (Video Phone 8875)
от 3 до 3.3(1) (Cisco Desk Phone 9800)
до 14.3 включительно (Cisco IP Phone 7800)
от 14.3 до 14.3(1)SR2 (Cisco IP Phone 7800)
до 14.3 включительно (Cisco IP Phone 8800)
от 14.3 до 14.3(1)SR2 (Cisco IP Phone 8800)
до 11 включительно (Cisco IP Phone 8821)
от 11 до 11.0(6)SR7 (Cisco IP Phone 8821)
от 3 до 3.3(1) (Video Phone 8875)

Тип ПО

Прикладное ПО информационных систем

Операционные системы и аппаратные платформы

-

Уровень опасности уязвимости

Средний уровень опасности (базовая оценка CVSS 2.0 составляет 5)
Средний уровень опасности (базовая оценка CVSS 3.1 составляет 5,3)

Возможные меры по устранению уязвимости

Использование рекомендаций производителя:
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-phone-write-g3kcC5Df

Статус уязвимости

Подтверждена производителем

Наличие эксплойта

Данные уточняются

Информация об устранении

Уязвимость устранена

Идентификаторы других систем описаний уязвимостей

EPSS

Процентиль: 27%
0.00349
Низкий

5.3 Medium

CVSS3

5 Medium

CVSS2

Связанные уязвимости

CVSS3: 5.3
nvd
12 месяцев назад

A vulnerability in the directory permissions of Cisco Desk Phone 9800 Series, Cisco IP Phone 7800 and 8800 Series, and Cisco Video Phone 8875 could allow an unauthenticated, remote attacker to access sensitive information on an affected device. This vulnerability exists because the product exposes sensitive information to an actor that is not explicitly authorized to have access to that information. An attacker could exploit this vulnerability by sending a crafted packet to the IP address of a device that has Web Access enabled. A successful exploit could allow the attacker to access sensitive information from the device. Note: To exploit this vulnerability, Web Access must be enabled on the phone. Web Access is disabled by default.

CVSS3: 7.5
github
8 месяцев назад

A vulnerability in the directory permissions of Cisco Desk Phone 9800 Series, Cisco IP Phone 7800 and 8800 Series, and Cisco Video Phone 8875 could allow an unauthenticated, remote attacker to access sensitive information on an affected device. This vulnerability exists because the product exposes sensitive information to an actor that is not explicitly authorized to have access to that information. An attacker could exploit this vulnerability by sending a crafted packet to the IP address of a device that has Web Access enabled. A successful exploit could allow the attacker to access sensitive information from the device. Note: To exploit this vulnerability, Web Access must be enabled on the phone. Web Access is disabled by default.

EPSS

Процентиль: 27%
0.00349
Низкий

5.3 Medium

CVSS3

5 Medium

CVSS2