Improper Authentication in Cisco Systems, Inc products - CVE-2023-20018

 

Improper Authentication in Cisco Systems, Inc products - CVE-2023-20018

Published: January 11, 2023


Vulnerability identifier: #VU71105
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2023-20018
CWE-ID: CWE-287
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to bypass authentication process.

The vulnerability exists due to an error when processing authentication requests in the web-based management interface. A remote attacker can bypass authentication process and gain unauthorized access to the device.


Affected software

IP Phone 7800 Series
SIP IP Phone Software
Cisco IP Phone 8800 Series

How to mitigate CVE-2023-20018

Install updates from vendor's website.

SIP IP Phone Software - addressed in versions 11.0.6 SR4, 14.1.1 SR2

External References

Related Security Bulletins