QID 730081

Date Published: 2021-05-20

QID 730081: Cisco IP Phones Call Log Information Disclosure Vulnerability (cisco-sa-phone-logs-2O7f7ExM)

A vulnerability in the Web Access feature of Cisco IP Phones could allow an
unauthenticated, remote attacker to view sensitive information on an affected device. Affected Products
Cisco IP Phones if they were running firmware that was compatible with Cisco Unified Communications Manager
releases 12.8(1) and earlier and had the Web Access feature enabled:
6900 Series
7800 Series
7900 Series
8800 Series
8900 Series
9900 Series

QID Detection Logic(Unauthenticated):
The QID sends a get request on "CGI/Java/Serviceability?adapter=device.statistics.device" and checks for the vulnerable version in the response.

A successful attack could allow the attacker to view sensitive information, including device call logs that
contain names, usernames, and phone numbers of users of the device.

  • CVSS V3 rated as Medium - 5.3 severity.
  • CVSS V2 rated as Medium - 5 severity.
  • Solution

    Customers are advised to refer to cisco-sa-phone-logs-2O7f7ExM for more information.

    CVEs related to QID 730081

    Software Advisories
    Advisory ID Software Component Link
    cisco-sa-phone-logs-2O7f7ExM URL Logo tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-phone-logs-2O7f7ExM