Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2019-1764

Опубликовано: 22 мар. 2019
Источник: nvd
CVSS3: 8.1
CVSS3: 8.8
CVSS2: 6.8
EPSS Низкий

Описание

A vulnerability in the web-based management interface of Session Initiation Protocol (SIP) Software for Cisco IP Phone 8800 Series could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack. The vulnerability is due to insufficient CSRF protections for the web-based management interface of an affected device. An attacker could exploit this vulnerability by persuading an authenticated user of the interface to follow a crafted link. A successful exploit could allow the attacker to perform arbitrary actions on a targeted device via a web browser and with the privileges of the user. This vulnerability affects Cisco IP Phone 8800 Series products running a SIP Software release prior to 11.0(5) for Wireless IP Phone 8821 and 8821-EX; and 12.5(1)SR1 for the IP Conference Phone 8832 and the rest of the IP Phone 8800 Series. Cisco IP Conference Phone 8831 is not affected.

Уязвимые конфигурации

Конфигурация 1

Одновременно

cpe:2.3:o:cisco:ip_phone_8821_firmware:*:*:*:*:*:*:*:*
Версия до 11.0\(5\) (исключая)
cpe:2.3:h:cisco:ip_phone_8821:-:*:*:*:*:*:*:*
Конфигурация 2

Одновременно

cpe:2.3:o:cisco:ip_phone_8821-ex_firmware:*:*:*:*:*:*:*:*
Версия до 11.0\(5\) (исключая)
cpe:2.3:h:cisco:ip_phone_8821-ex:-:*:*:*:*:*:*:*
Конфигурация 3

Одновременно

cpe:2.3:o:cisco:ip_conference_phone_8832_firmware:*:*:*:*:*:*:*:*
Версия до 12.5\(1\)sr1 (исключая)
cpe:2.3:h:cisco:ip_conference_phone_8832:-:*:*:*:*:*:*:*
Конфигурация 4

Одновременно

cpe:2.3:o:cisco:ip_phone_8800_firmware:*:*:*:*:*:*:*:*
Версия до 12.5\(1\)sr1 (исключая)
cpe:2.3:h:cisco:ip_phone_8800:-:*:*:*:*:*:*:*

EPSS

Процентиль: 41%
0.00189
Низкий

8.1 High

CVSS3

8.8 High

CVSS3

6.8 Medium

CVSS2

Дефекты

CWE-352
CWE-352

Связанные уязвимости

CVSS3: 8.8
github
больше 3 лет назад

A vulnerability in the web-based management interface of Session Initiation Protocol (SIP) Software for Cisco IP Phone 8800 Series could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack. The vulnerability is due to insufficient CSRF protections for the web-based management interface of an affected device. An attacker could exploit this vulnerability by persuading an authenticated user of the interface to follow a crafted link. A successful exploit could allow the attacker to perform arbitrary actions on a targeted device via a web browser and with the privileges of the user. This vulnerability affects Cisco IP Phone 8800 Series products running a SIP Software release prior to 11.0(5) for Wireless IP Phone 8821 and 8821-EX; and 12.5(1)SR1 for the IP Conference Phone 8832 and the rest of the IP Phone 8800 Series. Cisco IP Conference Phone 8831 is not affected.

CVSS3: 8.1
fstec
почти 7 лет назад

Уязвимость веб-интерфейса микропрограммного обеспечения IP-телефонов Cisco IP Phone серии 8800, позволяющая нарушителю выполнить произвольные действия в уязвимом устройстве

EPSS

Процентиль: 41%
0.00189
Низкий

8.1 High

CVSS3

8.8 High

CVSS3

6.8 Medium

CVSS2

Дефекты

CWE-352
CWE-352