XML External Entity injection in Cisco Systems, Inc products - CVE-2024-20357
Published: May 2, 2024
Vulnerability identifier: #VU89097
CSH Severity: Medium
CVSSv4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:U/U:Green
CVE-ID: CVE-2024-20357
CWE-ID: CWE-611
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerable software:
IP Phone 6800 Series with Multiplatform Firmware
IP Phone 7800 Series with Multiplatform Firmware
Cisco IP Phone 8800 Series with Multiplatform Firmware
Video Phone 8875 in Multiplatform Mode
IP Phone 6800 Series with Multiplatform Firmware
IP Phone 7800 Series with Multiplatform Firmware
Cisco IP Phone 8800 Series with Multiplatform Firmware
Video Phone 8875 in Multiplatform Mode
Software vendor:
Cisco Systems, Inc
Cisco Systems, Inc
Description
The vulnerability allows a remote attacker to initiate phone calls on the target device.
The vulnerability exists due to insufficient validation of user-supplied XML input. A remote attacker can pass a specially crafted XML code to the affected application and initiate calls or play sounds on the target device.
Remediation
Install updates from vendor's website.