VendorsCiscounified_sip_phone_3905all versions
Vulnerabilities

Cisco Unified SIP Phone 3905

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

3CVEs
CVE-2014-0721
The Cisco Unified SIP Phone 3905 with firmware before 9.4(1) allows remote attackers to obtain root access via a session on the test interface on TCP port 7870, aka Bug ID CSCuh75574.
Published 2014-02-22 · Modified
10.0EPSS 0.029
CVE-2023-20265
A vulnerability in the web-based management interface of a small subset of Cisco IP Phones could allow an authenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack against a user of the interface on an affected device. This vulnerability is due to insufficient validation of user-supplied input. An attacker could exploit this vulnerability by persuading a user of an affected interface to view a page containing malicious HTML or script content. A successful exploit could allow the attacker to execute arbitrary script code in the context of the affected interface or access sensitive, browser-based information. To exploit this vulnerability, the attacker must have valid credentials to access the web-based management interface of the affected device.
Published 2023-11-21 · Modified
5.5EPSS 0.005
CVE-2022-20660
Cisco IP Phones Information Disclosure Vulnerability
Published 2022-01-14 · Modified
4.6EPSS 0.004