Cisco IP Phone 7800
cpe:2.3:h:cisco:ip_phone_7800:*:*:*:*:*:*:*, +4 more
A vulnerability exists in the directory permissions of Cisco Desk Phone 9800 Series, Cisco IP Phone 7800 and 8800 Series, and Cisco Video Phone 8875, all running Cisco SIP Software. This vulnerability allows an unauthenticated, remote attacker to access sensitive information on the affected device. The issue arises because the product improperly exposes sensitive information to unauthorized actors. Exploitation requires Web Access to be enabled on the phone, which is disabled by default.
Successful exploitation allows access to sensitive information on the affected device.
Cisco has released software updates to address this vulnerability. Instructions for upgrading can be found in the Cisco Security Vulnerability Policy.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.