Логотип exploitDog
bind:CVE-2024-20357
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2024-20357

Количество 3

Количество 3

nvd логотип

CVE-2024-20357

почти 2 года назад

A vulnerability in the XML service of Cisco IP Phone firmware could allow an unauthenticated, remote attacker to initiate phone calls on an affected device. This vulnerability exists because bounds-checking does not occur while parsing XML requests. An attacker could exploit this vulnerability by sending a crafted XML request to an affected device. A successful exploit could allow the attacker to initiate calls or play sounds on the device.

CVSS3: 5.9
EPSS: Низкий
github логотип

GHSA-49gp-r5pw-pqg8

почти 2 года назад

A vulnerability in the XML service of Cisco IP Phone firmware could allow an unauthenticated, remote attacker to initiate phone calls on an affected device. This vulnerability exists because bounds-checking does not occur while parsing XML requests. An attacker could exploit this vulnerability by sending a crafted XML request to an affected device. A successful exploit could allow the attacker to initiate calls or play sounds on the device.

CVSS3: 5.9
EPSS: Низкий
fstec логотип

BDU:2024-03817

почти 2 года назад

Уязвимость веб-интерфейса управления микропрограммного обеспечения IP-телефонов Cisco IP Phone 6800, Cisco IP Phone 7800, Cisco IP Phone 8800 и Cisco Video Phone 8875, позволяющая нарушителю инициировать телефонные звонки на уязвимом устройстве

CVSS3: 5.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2024-20357

A vulnerability in the XML service of Cisco IP Phone firmware could allow an unauthenticated, remote attacker to initiate phone calls on an affected device. This vulnerability exists because bounds-checking does not occur while parsing XML requests. An attacker could exploit this vulnerability by sending a crafted XML request to an affected device. A successful exploit could allow the attacker to initiate calls or play sounds on the device.

CVSS3: 5.9
1%
Низкий
почти 2 года назад
github логотип
GHSA-49gp-r5pw-pqg8

A vulnerability in the XML service of Cisco IP Phone firmware could allow an unauthenticated, remote attacker to initiate phone calls on an affected device. This vulnerability exists because bounds-checking does not occur while parsing XML requests. An attacker could exploit this vulnerability by sending a crafted XML request to an affected device. A successful exploit could allow the attacker to initiate calls or play sounds on the device.

CVSS3: 5.9
1%
Низкий
почти 2 года назад
fstec логотип
BDU:2024-03817

Уязвимость веб-интерфейса управления микропрограммного обеспечения IP-телефонов Cisco IP Phone 6800, Cisco IP Phone 7800, Cisco IP Phone 8800 и Cisco Video Phone 8875, позволяющая нарушителю инициировать телефонные звонки на уязвимом устройстве

CVSS3: 5.3
1%
Низкий
почти 2 года назад

Уязвимостей на страницу