A vulnerability in the XML service of Cisco IP Phone firmware could allow an unauthenticated, remote attacker to initiate phone calls on an affected device.
This vulnerability exists because bounds-checking does not occur while parsing XML requests. An attacker could exploit this vulnerability by sending a crafted XML request to an affected device. A successful exploit could allow the attacker to initiate calls or play sounds on the device.
References
Configurations
Configuration 1 (hide)
| AND |
|
Configuration 2 (hide)
| AND |
|
Configuration 3 (hide)
| AND |
|
Configuration 4 (hide)
| AND |
|
Configuration 5 (hide)
| AND |
|
Configuration 6 (hide)
| AND |
|
Configuration 7 (hide)
| AND |
|
Configuration 8 (hide)
| AND |
|
Configuration 9 (hide)
| AND |
|
Configuration 10 (hide)
| AND |
|
Configuration 11 (hide)
| AND |
|
Configuration 12 (hide)
| AND |
|
Configuration 13 (hide)
| AND |
|
Configuration 14 (hide)
| AND |
|
Configuration 15 (hide)
| AND |
|
Configuration 16 (hide)
| AND |
|
Configuration 17 (hide)
| AND |
|
Configuration 18 (hide)
| AND |
|
History
05 Jan 2026, 14:57
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ipphone-multi-vulns-cXAhCvS - Vendor Advisory | |
| First Time |
Cisco ip Phone 8845
Cisco ip Phone 7821 Cisco ip Phone 6861 With Multiplatform Firmware Cisco ip Phone 7832 Cisco ip Phone 6841 With Multiplatform Firmware Cisco ip Phone 8832 With Multiplatform Firmware Cisco ip Phone 7841 Cisco ip Phone 7821 With Multiplatform Firmware Cisco ip Phone 6851 With Multiplatform Firmware Cisco ip Phone 7811 Cisco ip Phone 6871 Cisco ip Phone 8841 With Multiplatform Firmware Cisco ip Phone 8861 Cisco ip Phone 8865 With Multiplatform Firmware Cisco ip Phone 8861 With Multiplatform Firmware Cisco ip Phone 7811 With Multiplatform Firmware Cisco ip Phone 8845 With Multiplatform Firmware Cisco video Phone 8875 Firmware Cisco Cisco ip Phone 7861 Cisco ip Phone 8865 Cisco ip Phone 8841 Cisco ip Phone 6871 With Multiplatform Firmware Cisco ip Phone 8811 Cisco ip Phone 6851 Cisco ip Phone 6861 Cisco ip Phone 8851 With Multiplatform Firmware Cisco ip Phone 6841 Cisco ip Phone 8851 Cisco ip Phone 8811 With Multiplatform Firmware Cisco ip Phone 6821 Cisco ip Phone 7861 With Multiplatform Firmware Cisco ip Phone 6821 With Multiplatform Firmware Cisco ip Phone 7841 With Multiplatform Firmware Cisco ip Phone 8832 Cisco ip Phone 7832 With Multiplatform Firmware Cisco video Phone 8875 |
|
| CPE | cpe:2.3:o:cisco:ip_phone_6851_with_multiplatform_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:cisco:ip_phone_8832_with_multiplatform_firmware:*:*:*:*:*:*:*:* cpe:2.3:h:cisco:ip_phone_7832:-:*:*:*:*:*:*:* cpe:2.3:o:cisco:ip_phone_6861_with_multiplatform_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:cisco:ip_phone_6821_with_multiplatform_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:cisco:ip_phone_7861_with_multiplatform_firmware:*:*:*:*:*:*:*:* cpe:2.3:h:cisco:ip_phone_8865:-:*:*:*:*:*:*:* cpe:2.3:h:cisco:ip_phone_6871:-:*:*:*:*:*:*:* cpe:2.3:h:cisco:ip_phone_8811:-:*:*:*:*:*:*:* cpe:2.3:o:cisco:ip_phone_7811_with_multiplatform_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:cisco:ip_phone_8861_with_multiplatform_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:cisco:ip_phone_8845_with_multiplatform_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:cisco:ip_phone_7832_with_multiplatform_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:cisco:ip_phone_8851_with_multiplatform_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:cisco:ip_phone_7841_with_multiplatform_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:cisco:ip_phone_6841_with_multiplatform_firmware:*:*:*:*:*:*:*:* cpe:2.3:h:cisco:ip_phone_8861:-:*:*:*:*:*:*:* cpe:2.3:h:cisco:ip_phone_6861:-:*:*:*:*:*:*:* cpe:2.3:h:cisco:ip_phone_7861:-:*:*:*:*:*:*:* cpe:2.3:o:cisco:ip_phone_6871_with_multiplatform_firmware:*:*:*:*:*:*:*:* cpe:2.3:h:cisco:ip_phone_7821:-:*:*:*:*:*:*:* cpe:2.3:h:cisco:ip_phone_6821:-:*:*:*:*:*:*:* cpe:2.3:h:cisco:ip_phone_7811:-:*:*:*:*:*:*:* cpe:2.3:o:cisco:ip_phone_8811_with_multiplatform_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:cisco:video_phone_8875_firmware:*:*:*:*:*:*:*:* cpe:2.3:h:cisco:ip_phone_8851:-:*:*:*:*:*:*:* cpe:2.3:h:cisco:ip_phone_6841:-:*:*:*:*:*:*:* cpe:2.3:h:cisco:ip_phone_7841:-:*:*:*:*:*:*:* cpe:2.3:h:cisco:video_phone_8875:-:*:*:*:*:*:*:* cpe:2.3:h:cisco:ip_phone_6851:-:*:*:*:*:*:*:* cpe:2.3:o:cisco:ip_phone_7821_with_multiplatform_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:cisco:ip_phone_8841_with_multiplatform_firmware:*:*:*:*:*:*:*:* cpe:2.3:h:cisco:ip_phone_8841:-:*:*:*:*:*:*:* cpe:2.3:h:cisco:ip_phone_8832:-:*:*:*:*:*:*:* cpe:2.3:h:cisco:ip_phone_8845:-:*:*:*:*:*:*:* cpe:2.3:o:cisco:ip_phone_8865_with_multiplatform_firmware:*:*:*:*:*:*:*:* |
21 Nov 2024, 08:52
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ipphone-multi-vulns-cXAhCvS - | |
| Summary |
|
01 May 2024, 17:15
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2024-05-01 17:15
Updated : 2026-01-05 14:57
NVD link : CVE-2024-20357
Mitre link : CVE-2024-20357
CVE.ORG link : CVE-2024-20357
JSON object : View
Products Affected
cisco
- ip_phone_6851
- ip_phone_7811_with_multiplatform_firmware
- ip_phone_7841_with_multiplatform_firmware
- ip_phone_6821
- ip_phone_7832_with_multiplatform_firmware
- ip_phone_8845
- ip_phone_8851_with_multiplatform_firmware
- ip_phone_8811
- ip_phone_8861
- ip_phone_6861_with_multiplatform_firmware
- ip_phone_7821
- ip_phone_8861_with_multiplatform_firmware
- ip_phone_8841
- ip_phone_8841_with_multiplatform_firmware
- ip_phone_8832
- ip_phone_6841
- ip_phone_7811
- ip_phone_7821_with_multiplatform_firmware
- ip_phone_8845_with_multiplatform_firmware
- ip_phone_6871_with_multiplatform_firmware
- ip_phone_6861
- ip_phone_8865
- ip_phone_6821_with_multiplatform_firmware
- ip_phone_8832_with_multiplatform_firmware
- ip_phone_7841
- ip_phone_6851_with_multiplatform_firmware
- ip_phone_7832
- ip_phone_8811_with_multiplatform_firmware
- ip_phone_7861_with_multiplatform_firmware
- ip_phone_6841_with_multiplatform_firmware
- ip_phone_8851
- ip_phone_8865_with_multiplatform_firmware
- video_phone_8875
- ip_phone_7861
- ip_phone_6871
- video_phone_8875_firmware
CWE
CWE-787
Out-of-bounds Write
