CVE-2023-20265

5.5MEDIUM

Key Information

Vendor
Cisco
Status
Cisco Ip Phones With Multiplatform Firmware
Cisco Session Initiation Protocol (sip) Software
Vendor
CVE Published:
21 November 2023

Badges

👾 Exploit Exists

Summary

A vulnerability in the web-based management interface of a small subset of Cisco IP Phones could allow an authenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack against a user of the interface on an affected device. This vulnerability is due to insufficient validation of user-supplied input. An attacker could exploit this vulnerability by persuading a user of an affected interface to view a page containing malicious HTML or script content. A successful exploit could allow the attacker to execute arbitrary script code in the context of the affected interface or access sensitive, browser-based information. To exploit this vulnerability, the attacker must have valid credentials to access the web-based management interface of the affected device.

Affected Version(s)

Cisco IP Phones with Multiplatform Firmware = 4.5

Cisco IP Phones with Multiplatform Firmware = 4.6 MSR1

Cisco IP Phones with Multiplatform Firmware = 4.7.1

CVSS V3.1

Score:
5.5
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Changed

Timeline

  • 👾

    Exploit exists.

  • Risk change from: 5.4 to: 5.5 - (MEDIUM)

  • Vulnerability published.

  • Vulnerability Reserved.

Collectors

NVD DatabaseMitre Database
.