VendorsCiscoip_phone_8800all versions
Vulnerabilities

Cisco IP Phone 8800

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

12CVEs
CVE-2019-1716
Cisco IP Phone 7800 Series and 8800 Series Remote Code Execution Vulnerability
Published 2019-03-22 · Modified
9.8EPSS 0.031
CVE-2019-1764
Cisco IP Phone 8800 Series Cross-Site Request Forgery Vulnerability
Published 2019-03-22 · Modified
8.8EPSS 0.007
CVE-2023-20018
A vulnerability in the web-based management interface of Cisco IP Phone 7800 and 8800 Series Phones could allow an unauthenticated, remote attacker to bypass authentication on an affected device. This vulnerability is due to insufficient validation of user-supplied input. An attacker could exploit this vulnerability by sending a crafted request to the web-based management interface. A successful exploit could allow the attacker to access certain parts of the web interface that would normally require authentication.
Published 2023-01-19 · Modified
8.6EPSS 0.006
CVE-2019-1765
Cisco IP Phone 8800 Series Path Traversal Vulnerability
Published 2019-03-22 · Modified
8.1EPSS 0.014
CVE-2016-1479
Cisco IP Phone 8800 devices with software 11.0(1) allow remote attackers to cause a denial of service (memory corruption) via a crafted HTTP request, aka Bug ID CSCuz03038.
Published 2016-08-22 · Modified
7.8EPSS 0.030
CVE-2018-0325
A vulnerability in the Session Initiation Protocol (SIP) call-handling functionality of Cisco IP Phone 7800 Series phones and Cisco IP Phone 8800 Series phones could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected phone. The vulnerability is due to incomplete input validation of SIP Session Description Protocol (SDP) parameters by the SDP parser of an affected phone. An attacker could exploit this vulnerability by sending a malformed SIP packet to an affected phone. A successful exploit could allow the attacker to cause all active phone calls on the affected phone to be dropped while the SIP process on the phone unexpectedly restarts, resulting in a DoS condition. Cisco Bug IDs: CSCvf40066.
Published 2018-05-17 · Modified
7.5EPSS 0.033
CVE-2019-1763
Cisco IP Phone 8800 Series Authorization Bypass Vulnerability
Published 2019-03-22 · Modified
7.5EPSS 0.019
CVE-2019-1766
Cisco IP Phone 8800 Series File Upload Denial of Service Vulnerability
Published 2019-03-22 · Modified
7.5EPSS 0.015
CVE-2016-1435
Cisco 8800 phones with software 11.0(1) do not properly enforce mounted-filesystem permissions, which allows local users to write to arbitrary files by leveraging shell access, aka Bug ID CSCuz03014.
Published 2016-06-23 · Modified
7.0EPSS 0.003
CVE-2016-1434
The license-certificate upload functionality on Cisco 8800 phones with software 11.0(1) allows remote authenticated users to delete arbitrary files via an invalid file, aka Bug ID CSCuz03010.
Published 2016-06-23 · Modified
6.5EPSS 0.008
CVE-2019-1684
Cisco IP Phone 7800 and 8800 Series Cisco Discovery Protocol and Link Layer Discovery Protocol Denial of Service Vulnerability
Published 2019-02-21 · Modified
6.5EPSS 0.006
CVE-2016-1476
Cross-site scripting (XSS) vulnerability on Cisco IP Phone 8800 devices with software 11.0 allows remote authenticated users to inject arbitrary web script or HTML via crafted parameters, aka Bug ID CSCuz03024.
Published 2016-08-22 · Modified
5.4EPSS 0.008