ID

VAR-202006-1154


CVE

CVE-2020-3360


TITLE

Cisco IP Phones series 7800 and 8800 Vulnerability regarding information leakage in

Trust: 0.8

sources: JVNDB: JVNDB-2020-006923

DESCRIPTION

A vulnerability in the Web Access feature of Cisco IP Phones Series 7800 and Series 8800 could allow an unauthenticated, remote attacker to view sensitive information on an affected device. The vulnerability is due to improper access controls on the web-based management interface of an affected device. An attacker could exploit this vulnerability by sending malicious requests to the device, which could allow the attacker to bypass access restrictions. A successful attack could allow the attacker to view sensitive information, including device call logs that contain names, usernames, and phone numbers of users of the device

Trust: 1.62

sources: NVD: CVE-2020-3360 // JVNDB: JVNDB-2020-006923

AFFECTED PRODUCTS

vendor:ciscomodel:unified ip phone 7937gscope:lteversion:12.8\(1\)

Trust: 1.0

vendor:ciscomodel:unified ip phone 8851scope:lteversion:12.8\(1\)

Trust: 1.0

vendor:ciscomodel:unified ip phone 7962gscope:lteversion:12.8\(1\)

Trust: 1.0

vendor:ciscomodel:unified ip phone 8845scope:lteversion:12.8\(1\)

Trust: 1.0

vendor:ciscomodel:unified ip phone 9971scope:lteversion:12.8\(1\)

Trust: 1.0

vendor:ciscomodel:unified ip phone 8945scope:lteversion:12.8\(1\)

Trust: 1.0

vendor:ciscomodel:unified ip phone 7975gscope:lteversion:12.8\(1\)

Trust: 1.0

vendor:ciscomodel:unified ip phone 7861scope:lteversion:12.8\(1\)

Trust: 1.0

vendor:ciscomodel:unified ip phone 7960gscope:lteversion:12.8\(1\)

Trust: 1.0

vendor:ciscomodel:unified ip phone 8841scope:lteversion:12.8\(1\)

Trust: 1.0

vendor:ciscomodel:unified ip phone 7811scope:lteversion:12.8\(1\)

Trust: 1.0

vendor:ciscomodel:unified ip phone 7832scope:lteversion:12.8\(1\)

Trust: 1.0

vendor:ciscomodel:unified ip phone 6901scope:lteversion:12.8\(1\)

Trust: 1.0

vendor:ciscomodel:unified ip phone 7945gscope:lteversion:12.8\(1\)

Trust: 1.0

vendor:ciscomodel:unified ip phone 8865nrscope:lteversion:12.8\(1\)

Trust: 1.0

vendor:ciscomodel:unified ip phone 9951scope:lteversion:12.8\(1\)

Trust: 1.0

vendor:ciscomodel:unified ip phone 6945scope:lteversion:12.8\(1\)

Trust: 1.0

vendor:ciscomodel:unified ip phone 7961gscope:lteversion:12.8\(1\)

Trust: 1.0

vendor:ciscomodel:unified ip phone 7942gscope:lteversion:12.8\(1\)

Trust: 1.0

vendor:ciscomodel:unified ip phone 6911scope:lteversion:12.8\(1\)

Trust: 1.0

vendor:ciscomodel:unified ip phone 7965gscope:lteversion:12.8\(1\)

Trust: 1.0

vendor:ciscomodel:unified ip phone 8941scope:lteversion:12.8\(1\)

Trust: 1.0

vendor:ciscomodel:unified ip phone 8861scope:lteversion:12.8\(1\)

Trust: 1.0

vendor:ciscomodel:unified ip phone 7940gscope:lteversion:12.8\(1\)

Trust: 1.0

vendor:ciscomodel:unified ip phone 7841scope:lteversion:12.8\(1\)

Trust: 1.0

vendor:ciscomodel:unified ip phone 8865scope:lteversion:12.8\(1\)

Trust: 1.0

vendor:ciscomodel:unified ip phone 6961scope:lteversion:12.8\(1\)

Trust: 1.0

vendor:ciscomodel:unified ip phone 7821scope:lteversion:12.8\(1\)

Trust: 1.0

vendor:ciscomodel:unified ip phone 6941scope:lteversion:12.8\(1\)

Trust: 1.0

vendor:ciscomodel:unified ip phone 7906gscope:lteversion:12.8\(1\)

Trust: 1.0

vendor:ciscomodel:unified ip phone 8851nrscope:lteversion:12.8\(1\)

Trust: 1.0

vendor:ciscomodel:unified ip phone 7941gscope:lteversion:12.8\(1\)

Trust: 1.0

vendor:ciscomodel:unified ip phone 6921scope:lteversion:12.8\(1\)

Trust: 1.0

vendor:ciscomodel:unified ip phone 7931gscope:lteversion:12.8\(1\)

Trust: 1.0

vendor:ciscomodel:unified ip phone 8961scope:lteversion:12.8\(1\)

Trust: 1.0

vendor:ciscomodel:unified ip phone 8811scope:lteversion:12.8\(1\)

Trust: 1.0

vendor:ciscomodel:unified ip phone 7911gscope:lteversion:12.8\(1\)

Trust: 1.0

vendor:ciscomodel:unified ip phone 6901scope: - version: -

Trust: 0.8

vendor:ciscomodel:unified ip phone 6911scope: - version: -

Trust: 0.8

vendor:ciscomodel:unified ip phone 6921scope: - version: -

Trust: 0.8

vendor:ciscomodel:unified ip phone 6941scope: - version: -

Trust: 0.8

vendor:ciscomodel:unified ip phone 6945scope: - version: -

Trust: 0.8

vendor:ciscomodel:unified ip phone 6961scope: - version: -

Trust: 0.8

vendor:ciscomodel:unified ip phone 7821scope: - version: -

Trust: 0.8

vendor:ciscomodel:unified ip phone 7832scope: - version: -

Trust: 0.8

vendor:ciscomodel:unified ip phone 7841scope: - version: -

Trust: 0.8

vendor:ciscomodel:unified ip phone 7861scope: - version: -

Trust: 0.8

sources: JVNDB: JVNDB-2020-006923 // NVD: CVE-2020-3360

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2020-3360
value: MEDIUM

Trust: 1.0

ykramarz@cisco.com: CVE-2020-3360
value: MEDIUM

Trust: 1.0

NVD: JVNDB-2020-006923
value: MEDIUM

Trust: 0.8

CNNVD: CNNVD-202006-1136
value: MEDIUM

Trust: 0.6

nvd@nist.gov: CVE-2020-3360
severity: MEDIUM
baseScore: 5.0
vectorString: AV:N/AC:L/AU:N/C:P/I:N/A:N
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: NONE
availabilityImpact: NONE
exploitabilityScore: 10.0
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.0

NVD: JVNDB-2020-006923
severity: MEDIUM
baseScore: 5.0
vectorString: AV:N/AC:L/AU:N/C:P/I:N/A:N
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: NONE
availabilityImpact: NONE
exploitabilityScore: NONE
impactScore: NONE
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.8

nvd@nist.gov: CVE-2020-3360
baseSeverity: MEDIUM
baseScore: 5.3
vectorString: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
attackVector: NETWORK
attackComplexity: LOW
privilegesRequired: NONE
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: LOW
integrityImpact: NONE
availabilityImpact: NONE
exploitabilityScore: 3.9
impactScore: 1.4
version: 3.1

Trust: 1.0

ykramarz@cisco.com: CVE-2020-3360
baseSeverity: MEDIUM
baseScore: 5.3
vectorString: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
attackVector: NETWORK
attackComplexity: LOW
privilegesRequired: NONE
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: LOW
integrityImpact: NONE
availabilityImpact: NONE
exploitabilityScore: 3.9
impactScore: 1.4
version: 3.0

Trust: 1.0

NVD: JVNDB-2020-006923
baseSeverity: MEDIUM
baseScore: 5.3
vectorString: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
attackVector: NETWORK
attackComplexity: LOW
privilegesRequired: NONE
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: LOW
integrityImpact: NONE
availabilityImpact: NONE
exploitabilityScore: NONE
impactScore: NONE
version: 3.0

Trust: 0.8

sources: JVNDB: JVNDB-2020-006923 // CNNVD: CNNVD-202006-1136 // NVD: CVE-2020-3360 // NVD: CVE-2020-3360

PROBLEMTYPE DATA

problemtype:CWE-200

Trust: 1.8

problemtype:CWE-863

Trust: 1.0

sources: JVNDB: JVNDB-2020-006923 // NVD: CVE-2020-3360

THREAT TYPE

remote

Trust: 0.6

sources: CNNVD: CNNVD-202006-1136

TYPE

information disclosure

Trust: 0.6

sources: CNNVD: CNNVD-202006-1136

CONFIGURATIONS

sources: JVNDB: JVNDB-2020-006923

PATCH

title:cisco-sa-phone-logs-2O7f7ExMurl:https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-phone-logs-2O7f7ExM

Trust: 0.8

title:Cisco IP Phone 8800 Series and 7800 Series Repair measures for information disclosure vulnerabilitiesurl:http://www.cnnvd.org.cn/web/xxk/bdxqById.tag?id=121829

Trust: 0.6

sources: JVNDB: JVNDB-2020-006923 // CNNVD: CNNVD-202006-1136

EXTERNAL IDS

db:NVDid:CVE-2020-3360

Trust: 2.4

db:JVNDBid:JVNDB-2020-006923

Trust: 0.8

db:AUSCERTid:ESB-2020.2123

Trust: 0.6

db:NSFOCUSid:47187

Trust: 0.6

db:CNNVDid:CNNVD-202006-1136

Trust: 0.6

sources: JVNDB: JVNDB-2020-006923 // CNNVD: CNNVD-202006-1136 // NVD: CVE-2020-3360

REFERENCES

url:https://tools.cisco.com/security/center/content/ciscosecurityadvisory/cisco-sa-phone-logs-2o7f7exm

Trust: 1.6

url:https://nvd.nist.gov/vuln/detail/cve-2020-3360

Trust: 1.4

url:https://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2020-3360

Trust: 0.8

url:https://vigilance.fr/vulnerability/cisco-ip-phone-information-disclosure-via-call-log-32557

Trust: 0.6

url:http://www.nsfocus.net/vulndb/47187

Trust: 0.6

url:https://www.auscert.org.au/bulletins/esb-2020.2123/

Trust: 0.6

sources: JVNDB: JVNDB-2020-006923 // CNNVD: CNNVD-202006-1136 // NVD: CVE-2020-3360

CREDITS

Oguzhan Karaman of Turkish Technic

Trust: 0.6

sources: CNNVD: CNNVD-202006-1136

SOURCES

db:JVNDBid:JVNDB-2020-006923
db:CNNVDid:CNNVD-202006-1136
db:NVDid:CVE-2020-3360

LAST UPDATE DATE

2024-11-23T22:33:25.822000+00:00


SOURCES UPDATE DATE

db:JVNDBid:JVNDB-2020-006923date:2020-07-22T00:00:00
db:CNNVDid:CNNVD-202006-1136date:2021-08-09T00:00:00
db:NVDid:CVE-2020-3360date:2024-11-21T05:30:52.567

SOURCES RELEASE DATE

db:JVNDBid:JVNDB-2020-006923date:2020-07-22T00:00:00
db:CNNVDid:CNNVD-202006-1136date:2020-06-17T00:00:00
db:NVDid:CVE-2020-3360date:2020-06-18T03:15:14.403