QID 730873
QID 730873: Cisco IP Phone 6800, 7800, and 8800 Series with Multiplatform Firmware Cross-Site Request Forgery Vulnerability (cisco-sa-ipphone-csrf-HOCmXW2c)
A vulnerability in the web-based management interface of Cisco IP Phone 6800, 7800, and 8800 Series with Multiplatform Firmware could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack against a user of the web-based management interface of an affected system.
Affected Products
This vulnerability affects the following Cisco products if they are running a vulnerable release of Cisco Multiplatform Firmware:
IP Phone 6800 Series with Multiplatform Firmware
IP Phone 7800 Series with Multiplatform Firmware
IP Phone 8800 Series with Multiplatform Firmware
Cisco IP Conference Phone 8831 with Multiplatform Firmware
QID Detection Logic(Unauthenticated):
The QID sends a get request on "CGI/Java/Serviceability?adapter=device.statistics.device" and checks for the vulnerable version in the response.
A successful exploit could allow the attacker to perform a factory reset of the affected device, resulting in a Denial of Service (DoS) condition.
Customers are advised to refer to cisco-sa-ipphone-csrf-HOCmXW2c for more information.
- cisco-sa-ipphone-csrf-HOCmXW2c -
sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/ cisco-sa-ipphone-csrf-HOCmXW2c
CVEs related to QID 730873
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| cisco-sa-ipphone-csrf-HOCmXW2c |
|