#VU29143 Information disclosure in Cisco Systems, Inc products - CVE-2020-3360

 

#VU29143 Information disclosure in Cisco Systems, Inc products - CVE-2020-3360

Published: June 18, 2020


Vulnerability identifier: #VU29143
Vulnerability risk: Medium
CVSSv4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:U/U:Green
CVE-ID: CVE-2020-3360
CWE-ID: CWE-200
Exploitation vector: Remote access
Exploit availability: No public exploit available
Vulnerable software:
Cisco 7800 Series IP Phones
Cisco 8800 Series IP Phones
Unified Communications Manager (CallManager)
Software vendor:
Cisco Systems, Inc

Description

The vulnerability allows a remote attacker to gain access to potentially sensitive information.

The vulnerability exists due to improper access controls on the web-based management interface of an affected device within the Web Access feature. A remote attacker can send specially crafted requests, bypass access restrictions and gain unauthorized access to sensitive information, such as device call logs that contain names, usernames, and phone numbers of users of the device.


Remediation

Install updates from vendor's website.

External links