VDB

CVE-2020-3360

CVE-2020-3360 PUBLISHED CVSS 5.300000190734863 MEDIUM

A vulnerability in the Web Access feature of Cisco IP Phones Series 7800 and Series 8800 could allow an unauthenticated, remote attacker to view sensitive information on an affected device. The vulnerability is due to improper access controls on the web-based management interface of an affected device. An attacker could exploit this vulnerability by sending malicious requests to the device, which could allow the attacker to bypass access restrictions. A successful attack could allow the attacker to view sensitive information, including device call logs that contain names, usernames, and phone numbers of users of the device.

EPSS 0.36% · 58.4th percentile

Risk Scores

CVSS 3.0
5.300000190734863
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
EPSS Score
0.36%
58.4th percentile

Affected Products

VendorProductVersions
ciscounified_ip_phone_9951_firmware0
ciscounified_ip_phone_7821_firmware0
CiscoCisco IP Phone 8800 Series Softwaren/a
ciscounified_ip_phone_8811_firmware0
ciscounified_ip_phone_7945g_firmware0
ciscounified_ip_phone_8851nr_firmware0
ciscounified_ip_phone_7961g_firmware0
ciscounified_ip_phone_8865_firmware0
ciscounified_ip_phone_8961_firmware0
ciscounified_ip_phone_7906g_firmware0
ciscounified_ip_phone_6921_firmware0
ciscounified_ip_phone_6961_firmware0
ciscounified_ip_phone_9971_firmware0
ciscounified_ip_phone_6901_firmware0
ciscounified_ip_phone_8845_firmware0
ciscounified_ip_phone_7832_firmware0
ciscounified_ip_phone_7942g_firmware0
ciscounified_ip_phone_7861_firmware0
ciscounified_ip_phone_8861_firmware0
ciscounified_ip_phone_6941_firmware0

…and 18 more

Timeline

  • Jun 17, 2020 CVE Published
  • Apr 14, 2021 EPSS Score
  • Jun 23, 2021 EPSS Score
  • Aug 24, 2021 EPSS Score
  • Oct 26, 2021 EPSS Score
  • Jan 6, 2022 EPSS Score
  • Feb 4, 2022 EPSS Score
  • Feb 28, 2022 EPSS Score
  • Apr 1, 2022 EPSS Score
  • May 1, 2022 EPSS Score
  • Jul 3, 2022 EPSS Score
  • Sep 4, 2022 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›