VYPR
Unrated severityNVD Advisory· Published May 1, 2024· Updated Aug 1, 2024

CVE-2024-20376

CVE-2024-20376

Description

A vulnerability in the web-based management interface of Cisco IP Phone firmware could allow an unauthenticated, remote attacker to cause an affected device to reload, resulting in a DoS condition. This vulnerability is due to insufficient validation of user-supplied input. An attacker could exploit this vulnerability by sending a crafted request to the web-based management interface of an affected device. A successful exploit could allow the attacker to cause the affected device to reload.

Affected products

3
  • Cisco/Cisco IP Phones with Multiplatform Firmwarev5
    Range: 11.3.1 MSR2-6
  • Cisco/Cisco PhoneOSv5
    Range: 1.0.1

Patches

0

No patches discovered yet.

Vulnerability mechanics

No source-code context for this CVE — mechanics is only generated when we can read the actual fix diff. Without that, the four sections (root cause, attack vector, affected code, fix) would be speculation rather than analysis.

References

1

News mentions

0

No linked articles in our index yet.