Monday, April 14, 2025
HomeCVE/vulnerabilityCisco Desk Phone Series Vulnerability Lets Remote Attacker Access Sensitive Information

Cisco Desk Phone Series Vulnerability Lets Remote Attacker Access Sensitive Information

Published on

SIEM as a Service

Follow Us on Google News

A significant vulnerability (CVE-2024-20445) has been discovered in Cisco Desk Phone 9800 Series, IP Phone 7800 and 8800 Series, and Video Phone 8875 that could allow remote, unauthenticated attackers to access sensitive information.

This vulnerability, classified under CWE-200 (Exposure of Sensitive Information to an Unauthorized Actor), is due to improper storage of sensitive information within the web user interface (UI) of Session Initiation Protocol (SIP)-based phone software.

CVE-2024-20445 – Summary of the Vulnerability

The flaw stems from improper handling of sensitive information within the web UI, particularly when the Web Access feature is enabled.

- Advertisement - Google News

Attackers can exploit this vulnerability by simply browsing the IP address of an affected device.

Build an in-house SOC or outsource SOC-as-a-Service -> Calculate Costs

If successful, they could access sensitive data, including call records (both incoming and outgoing) stored on the device.

It is important to note that these devices’ Web Access feature is disabled by default, reducing the immediate risk.

However, in instances where it has been enabled, the vulnerability becomes exploitable.

Cisco has acknowledged the issue and promptly released software updates to address it. Unfortunately, this vulnerability has no workarounds beyond applying the fixed software versions.

Affected Products

At the time of publication, the following Cisco products were confirmed to be vulnerable if running a susceptible version of Cisco SIP IP Phone Software and Web Access was enabled:

  • Cisco Desk Phone 9800 Series
  • Cisco IP Phone 7800 Series
  • Cisco IP Phone 8800 Series (except the Wireless IP Phone 8821)
  • Cisco Video Phone 8875

Users must verify whether Web Access is enabled on their devices.

If so, disabling it or applying software updates should be considered immediate actions to protect against potential exploitation. 

Cisco has released software patches to address this issue. Users are urged to review the Cisco Security Advisories page regularly to ensure they run the latest, secure software versions.

When upgrading, users must ensure that devices have the necessary resources and support to function with the updated software.

Run private, Real-time Malware Analysis in both Windows & Linux VMs. Get a 14-day free trial with ANY.RUN!

Divya
Divya
Divya is a Senior Journalist at GBhackers covering Cyber Attacks, Threats, Breaches, Vulnerabilities and other happenings in the cyber world.

Latest articles

BPFDoor Malware Uses Reverse Shell to Expand Control Over Compromised Networks

A new wave of cyber espionage attacks has brought BPFDoor malware into the spotlight...

EU’s GDPR Article 7 Poses New Challenges for Businesses To Secure AI-Generated Image Data

As businesses worldwide embrace digital transformation, the European Union’s General Data Protection Regulation (GDPR),...

Morocco Investigation Major Data Breach Allegedly Claimed by Algerian Hackers

The National Social Security Fund (CNSS) of Morocco has confirmed that initial checks on...

Smishing Campaign Hits Toll Road Users with $5 Payment Scam

Cybersecurity researchers at Cisco Talos have uncovered a large-scale smishing campaign targeting toll road...

Resilience at Scale

Why Application Security is Non-Negotiable

The resilience of your digital infrastructure directly impacts your ability to scale. And yet, application security remains a critical weak link for most organizations.

Application Security is no longer just a defensive play—it’s the cornerstone of cyber resilience and sustainable growth. In this webinar, Karthik Krishnamoorthy (CTO of Indusface) and Phani Deepak Akella (VP of Marketing – Indusface), will share how AI-powered application security can help organizations build resilience by

Discussion points


Protecting at internet scale using AI and behavioral-based DDoS & bot mitigation.
Autonomously discovering external assets and remediating vulnerabilities within 72 hours, enabling secure, confident scaling.
Ensuring 100% application availability through platforms architected for failure resilience.
Eliminating silos with real-time correlation between attack surface and active threats for rapid, accurate mitigation

More like this

BPFDoor Malware Uses Reverse Shell to Expand Control Over Compromised Networks

A new wave of cyber espionage attacks has brought BPFDoor malware into the spotlight...

EU’s GDPR Article 7 Poses New Challenges for Businesses To Secure AI-Generated Image Data

As businesses worldwide embrace digital transformation, the European Union’s General Data Protection Regulation (GDPR),...

Morocco Investigation Major Data Breach Allegedly Claimed by Algerian Hackers

The National Social Security Fund (CNSS) of Morocco has confirmed that initial checks on...