SB2022012415 - Cleartext storage of sensitive information in Cisco IP Phones
Published: January 24, 2022
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Cleartext storage of sensitive information (CVE-ID: CVE-2022-20660)
The vulnerability allows a local attacker to gain access to potentially sensitive information.
The vulnerability exists due to unencrypted storage of confidential information. An attacker with physical access can obtain confidential information from the device.
Remediation
Install update from vendor's website.