CVE-2022-20817
A vulnerability in Cisco Unified IP Phones could allow an unauthenticated, remote attacker to impersonate another user's phone if the Cisco Unified Communications Manager (CUCM) is in secure mode. This vulnerability is due to improper key generation during the manufacturing process that could result in duplicated manufactured keys installed on multiple devices. An attacker could exploit this vulnerability by performing a machine-in-the-middle attack on the secure communication between the phone and the CUCM. A successful exploit could allow the attacker to impersonate another user's phone. This vulnerability cannot be addressed with software updates. There is a workaround that addresses this vulnerability.
EPSS 0.89% · 76.0th percentile
Risk Scores
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| cisco | unified_ip_phone_6911_firmware | |
| cisco | unified_ip_phone_9951_firmware | |
| cisco | unified_ip_phone_6921_firmware | |
| cisco | unified_ip_phone_8961_firmware | |
| Cisco | Cisco IP Phones with Multiplatform Firmware | n/a |
| cisco | unified_ip_phone_6961_firmware | |
| cisco | unified_ip_phone_6945_firmware | |
| cisco | unified_ip_phone_9971_firmware | |
| cisco | unified_ip_phone_8945_firmware | |
| cisco | unified_ip_phone_8941_firmware | |
| cisco | unified_ip_phone_6941_firmware | |
| cisco | ata_187_analog_telephone_adapter_firmware |
Exploit Intelligence
Timeline
- Jun 15, 2022 CVE Published
- Jun 16, 2022 EPSS Score
- Aug 4, 2022 EPSS Score
- Sep 21, 2022 EPSS Score
- Nov 8, 2022 EPSS Score
- Dec 26, 2022 EPSS Score
- Feb 12, 2023 EPSS Score
- Mar 7, 2023 EPSS Score
- Apr 1, 2023 EPSS Score
- Jul 6, 2023 EPSS Score
- Aug 23, 2023 EPSS Score
- Oct 10, 2023 EPSS Score
References
- 20220615 Cisco IP Phone Duplicate Key Vulnerability vendor-advisory
- https://nvd.nist.gov/vuln/detail/CVE-2022-20817 advisory