Improper Authentication in Cisco Systems, Inc products - CVE-2023-20018
Published: January 11, 2023
Vulnerability identifier: #VU71105
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2023-20018
CWE-ID: CWE-287
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to bypass authentication process.
The vulnerability exists due to an error when processing authentication requests in the web-based management interface. A remote attacker can bypass authentication process and gain unauthorized access to the device.
Affected software
IP Phone 7800 Series
SIP IP Phone Software
Cisco IP Phone 8800 Series
SIP IP Phone Software
Cisco IP Phone 8800 Series
How to mitigate CVE-2023-20018
Install updates from vendor's website.
SIP IP Phone Software - addressed in versions 11.0.6 SR4, 14.1.1 SR2