CVE-2023-20078: Triggering command injection in Cisco IP phones
ibm.com·23h·
Discuss: Hacker News
🧪CBOR Fuzzing
Preview
Report Post

CVE-2023-20078 catalogs an unauthenticated command injection vulnerability in the web-based management interface of Cisco 6800, 7800, and 8800 Series IP Phones with Multiplatform Firmware installed; however, limited technical analysis is publicly available. This article presents my findings while researching this vulnerability. In the end, the reader should be equipped with the information necessary to understand and trigger this vulnerability.

Vulnerability details

The following Cisco Security Advisory (Cisco IP Phone 6800, 7800, and 8800 Series Web UI Vulnerabilities – Cisco) details CVE-2023-20078 and CVE-2023-20079. This vulnerability affects Cisco 6800, 7800 and 8800 Series IP Phones w…

Similar Posts

Loading similar posts...