#VU29143 Information disclosure in Cisco Systems, Inc products - CVE-2020-3360
Published: June 18, 2020
Cisco 7800 Series IP Phones
Cisco 8800 Series IP Phones
Unified Communications Manager (CallManager)
Cisco Systems, Inc
Description
The vulnerability allows a remote attacker to gain access to potentially sensitive information.
The vulnerability exists due to improper access controls on the web-based management interface of an affected device within the Web Access feature. A remote attacker can send specially crafted requests, bypass access restrictions and gain unauthorized access to sensitive information, such as device call logs that contain names, usernames, and phone numbers of users of the device.