Improper Authentication in Cisco Systems, Inc products - CVE-2023-20018
Published: January 11, 2023
Vulnerability identifier: #VU71105
CSH Severity: Medium
CVSS v4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:U/U:Green
CVE-ID: CVE-2023-20018
CWE-ID: CWE-287
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vendor: Cisco Systems, Inc
Affected software:
IP Phone 7800 Series
SIP IP Phone Software
Cisco IP Phone 8800 Series
IP Phone 7800 Series
SIP IP Phone Software
Cisco IP Phone 8800 Series
Detailed vulnerability description
The vulnerability allows a remote attacker to bypass authentication process.
The vulnerability exists due to an error when processing authentication requests in the web-based management interface. A remote attacker can bypass authentication process and gain unauthorized access to the device.
How to mitigate CVE-2023-20018
Install updates from vendor's website.