A vulnerability in the XML service of Cisco IP Phone firmware could allow an unauthenticated, remote attacker to initiate phone calls on an affected device.
This vulnerability exists because bounds-checking does not occur while parsing XML requests. An attacker could exploit this vulnerability by sending a crafted XML request to an affected device. A successful exploit could allow the attacker to initiate calls or play sounds on the device.
This vulnerability exists because bounds-checking does not occur while parsing XML requests. An attacker could exploit this vulnerability by sending a crafted XML request to an affected device. A successful exploit could allow the attacker to initiate calls or play sounds on the device.
Project Subscriptions
| Vendors | Products |
|---|---|
|
Cisco
Subscribe
|
Ip Phone 6821
Subscribe
Ip Phone 6821 With Multiplatform Firmware
Subscribe
Ip Phone 6841
Subscribe
Ip Phone 6841 With Multiplatform Firmware
Subscribe
Ip Phone 6851
Subscribe
Ip Phone 6851 With Multiplatform Firmware
Subscribe
Ip Phone 6861
Subscribe
Ip Phone 6861 With Multiplatform Firmware
Subscribe
Ip Phone 6871
Subscribe
Ip Phone 6871 With Multiplatform Firmware
Subscribe
Ip Phone 7811
Subscribe
Ip Phone 7811 With Multiplatform Firmware
Subscribe
Ip Phone 7821
Subscribe
Ip Phone 7821 With Multiplatform Firmware
Subscribe
Ip Phone 7832
Subscribe
Ip Phone 7832 With Multiplatform Firmware
Subscribe
Ip Phone 7841
Subscribe
Ip Phone 7841 With Multiplatform Firmware
Subscribe
Ip Phone 7861
Subscribe
Ip Phone 7861 With Multiplatform Firmware
Subscribe
Ip Phone 8811
Subscribe
Ip Phone 8811 With Multiplatform Firmware
Subscribe
Ip Phone 8832
Subscribe
Ip Phone 8832 With Multiplatform Firmware
Subscribe
Ip Phone 8841
Subscribe
Ip Phone 8841 With Multiplatform Firmware
Subscribe
Ip Phone 8845
Subscribe
Ip Phone 8845 With Multiplatform Firmware
Subscribe
Ip Phone 8851
Subscribe
Ip Phone 8851 With Multiplatform Firmware
Subscribe
Ip Phone 8861
Subscribe
Ip Phone 8861 With Multiplatform Firmware
Subscribe
Ip Phone 8865
Subscribe
Ip Phone 8865 With Multiplatform Firmware
Subscribe
Video Phone 8875
Subscribe
Video Phone 8875 Firmware
Subscribe
|
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-18072 | A vulnerability in the XML service of Cisco IP Phone firmware could allow an unauthenticated, remote attacker to initiate phone calls on an affected device. This vulnerability exists because bounds-checking does not occur while parsing XML requests. An attacker could exploit this vulnerability by sending a crafted XML request to an affected device. A successful exploit could allow the attacker to initiate calls or play sounds on the device. |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Mon, 05 Jan 2026 15:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Cisco
Cisco ip Phone 6821 Cisco ip Phone 6821 With Multiplatform Firmware Cisco ip Phone 6841 Cisco ip Phone 6841 With Multiplatform Firmware Cisco ip Phone 6851 Cisco ip Phone 6851 With Multiplatform Firmware Cisco ip Phone 6861 Cisco ip Phone 6861 With Multiplatform Firmware Cisco ip Phone 6871 Cisco ip Phone 6871 With Multiplatform Firmware Cisco ip Phone 7811 Cisco ip Phone 7811 With Multiplatform Firmware Cisco ip Phone 7821 Cisco ip Phone 7821 With Multiplatform Firmware Cisco ip Phone 7832 Cisco ip Phone 7832 With Multiplatform Firmware Cisco ip Phone 7841 Cisco ip Phone 7841 With Multiplatform Firmware Cisco ip Phone 7861 Cisco ip Phone 7861 With Multiplatform Firmware Cisco ip Phone 8811 Cisco ip Phone 8811 With Multiplatform Firmware Cisco ip Phone 8832 Cisco ip Phone 8832 With Multiplatform Firmware Cisco ip Phone 8841 Cisco ip Phone 8841 With Multiplatform Firmware Cisco ip Phone 8845 Cisco ip Phone 8845 With Multiplatform Firmware Cisco ip Phone 8851 Cisco ip Phone 8851 With Multiplatform Firmware Cisco ip Phone 8861 Cisco ip Phone 8861 With Multiplatform Firmware Cisco ip Phone 8865 Cisco ip Phone 8865 With Multiplatform Firmware Cisco video Phone 8875 Cisco video Phone 8875 Firmware |
|
| CPEs | cpe:2.3:h:cisco:ip_phone_6821:-:*:*:*:*:*:*:* cpe:2.3:h:cisco:ip_phone_6841:-:*:*:*:*:*:*:* cpe:2.3:h:cisco:ip_phone_6851:-:*:*:*:*:*:*:* cpe:2.3:h:cisco:ip_phone_6861:-:*:*:*:*:*:*:* cpe:2.3:h:cisco:ip_phone_6871:-:*:*:*:*:*:*:* cpe:2.3:h:cisco:ip_phone_7811:-:*:*:*:*:*:*:* cpe:2.3:h:cisco:ip_phone_7821:-:*:*:*:*:*:*:* cpe:2.3:h:cisco:ip_phone_7832:-:*:*:*:*:*:*:* cpe:2.3:h:cisco:ip_phone_7841:-:*:*:*:*:*:*:* cpe:2.3:h:cisco:ip_phone_7861:-:*:*:*:*:*:*:* cpe:2.3:h:cisco:ip_phone_8811:-:*:*:*:*:*:*:* cpe:2.3:h:cisco:ip_phone_8832:-:*:*:*:*:*:*:* cpe:2.3:h:cisco:ip_phone_8841:-:*:*:*:*:*:*:* cpe:2.3:h:cisco:ip_phone_8845:-:*:*:*:*:*:*:* cpe:2.3:h:cisco:ip_phone_8851:-:*:*:*:*:*:*:* cpe:2.3:h:cisco:ip_phone_8861:-:*:*:*:*:*:*:* cpe:2.3:h:cisco:ip_phone_8865:-:*:*:*:*:*:*:* cpe:2.3:h:cisco:video_phone_8875:-:*:*:*:*:*:*:* cpe:2.3:o:cisco:ip_phone_6821_with_multiplatform_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:cisco:ip_phone_6841_with_multiplatform_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:cisco:ip_phone_6851_with_multiplatform_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:cisco:ip_phone_6861_with_multiplatform_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:cisco:ip_phone_6871_with_multiplatform_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:cisco:ip_phone_7811_with_multiplatform_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:cisco:ip_phone_7821_with_multiplatform_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:cisco:ip_phone_7832_with_multiplatform_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:cisco:ip_phone_7841_with_multiplatform_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:cisco:ip_phone_7861_with_multiplatform_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:cisco:ip_phone_8811_with_multiplatform_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:cisco:ip_phone_8832_with_multiplatform_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:cisco:ip_phone_8841_with_multiplatform_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:cisco:ip_phone_8845_with_multiplatform_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:cisco:ip_phone_8851_with_multiplatform_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:cisco:ip_phone_8861_with_multiplatform_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:cisco:ip_phone_8865_with_multiplatform_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:cisco:video_phone_8875_firmware:*:*:*:*:*:*:*:* |
|
| Vendors & Products |
Cisco
Cisco ip Phone 6821 Cisco ip Phone 6821 With Multiplatform Firmware Cisco ip Phone 6841 Cisco ip Phone 6841 With Multiplatform Firmware Cisco ip Phone 6851 Cisco ip Phone 6851 With Multiplatform Firmware Cisco ip Phone 6861 Cisco ip Phone 6861 With Multiplatform Firmware Cisco ip Phone 6871 Cisco ip Phone 6871 With Multiplatform Firmware Cisco ip Phone 7811 Cisco ip Phone 7811 With Multiplatform Firmware Cisco ip Phone 7821 Cisco ip Phone 7821 With Multiplatform Firmware Cisco ip Phone 7832 Cisco ip Phone 7832 With Multiplatform Firmware Cisco ip Phone 7841 Cisco ip Phone 7841 With Multiplatform Firmware Cisco ip Phone 7861 Cisco ip Phone 7861 With Multiplatform Firmware Cisco ip Phone 8811 Cisco ip Phone 8811 With Multiplatform Firmware Cisco ip Phone 8832 Cisco ip Phone 8832 With Multiplatform Firmware Cisco ip Phone 8841 Cisco ip Phone 8841 With Multiplatform Firmware Cisco ip Phone 8845 Cisco ip Phone 8845 With Multiplatform Firmware Cisco ip Phone 8851 Cisco ip Phone 8851 With Multiplatform Firmware Cisco ip Phone 8861 Cisco ip Phone 8861 With Multiplatform Firmware Cisco ip Phone 8865 Cisco ip Phone 8865 With Multiplatform Firmware Cisco video Phone 8875 Cisco video Phone 8875 Firmware |
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: cisco
Published:
Updated: 2024-08-01T21:59:42.103Z
Reserved: 2023-11-08T15:08:07.649Z
Link: CVE-2024-20357
Updated: 2024-08-01T21:59:42.103Z
Status : Analyzed
Published: 2024-05-01T17:15:28.143
Modified: 2026-01-05T14:57:54.070
Link: CVE-2024-20357
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD