XML External Entity injection in Cisco Systems, Inc products - CVE-2024-20357

 

XML External Entity injection in Cisco Systems, Inc products - CVE-2024-20357

Published: May 2, 2024


Vulnerability identifier: #VU89097
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2024-20357
CWE-ID: CWE-611
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to initiate phone calls on the target device.

The vulnerability exists due to insufficient validation of user-supplied XML input. A remote attacker can pass a specially crafted XML code to the affected application and initiate calls or play sounds on the target device.


Affected software

IP Phone 6800 Series with Multiplatform Firmware
IP Phone 7800 Series with Multiplatform Firmware
Cisco IP Phone 8800 Series with Multiplatform Firmware
Video Phone 8875 in Multiplatform Mode

How to mitigate CVE-2024-20357

Install updates from vendor's website.

IP Phone 6800 Series with Multiplatform Firmware - update to 12.0.4SR1
IP Phone 7800 Series with Multiplatform Firmware - update to 12.0.4SR1
Cisco IP Phone 8800 Series with Multiplatform Firmware - update to 12.0.4SR1
Video Phone 8875 in Multiplatform Mode - update to 2.3.1.0101

External References

Related Security Bulletins