ID

VAR-202411-2670


CVE

CVE-2024-20445


TITLE

Cisco IP Phone Information Disclosure Vulnerability

Trust: 0.6

sources: CNVD: CNVD-2025-05983

DESCRIPTION

A vulnerability in the web UI of Cisco Desk Phone 9800 Series, Cisco IP Phone 7800 and 8800 Series, and Cisco Video Phone 8875 could allow an unauthenticated, remote attacker to access sensitive information on an affected device. This vulnerability is due to improper storage of sensitive information within the web UI of Session Initiation Protocol (SIP)-based phone loads. An attacker could exploit this vulnerability by browsing to the IP address of a device that has Web Access enabled. A successful exploit could allow the attacker to access sensitive information, including incoming and outgoing call records. Note: Web Access is disabled by default. It is an IP phone that provides calling functions

Trust: 1.44

sources: NVD: CVE-2024-20445 // CNVD: CNVD-2025-05983

IOT TAXONOMY

category:['IoT']sub_category: -

Trust: 0.6

sources: CNVD: CNVD-2025-05983

AFFECTED PRODUCTS

vendor:ciscomodel:ip phone 7841scope:ltversion:14.3\(1\)

Trust: 1.0

vendor:ciscomodel:ip conference phone 7832scope:ltversion:14.3\(1\)

Trust: 1.0

vendor:ciscomodel:desk phone 9841scope:eqversion:3.1\(1\)

Trust: 1.0

vendor:ciscomodel:video phone 8875scope:eqversion:2.3\(1\)

Trust: 1.0

vendor:ciscomodel:ip phone 8845scope:ltversion:14.3\(1\)

Trust: 1.0

vendor:ciscomodel:video phone 8875scope:ltversion:2.3\(1\)

Trust: 1.0

vendor:ciscomodel:ip conference phone 8832scope:ltversion:14.3\(1\)

Trust: 1.0

vendor:ciscomodel:desk phone 9851scope:eqversion:3.1\(1\)

Trust: 1.0

vendor:ciscomodel:desk phone 9871scope:eqversion:3.1\(1\)

Trust: 1.0

vendor:ciscomodel:ip phone 8861scope:ltversion:14.3\(1\)

Trust: 1.0

vendor:ciscomodel:ip phone 7861scope:ltversion:14.3\(1\)

Trust: 1.0

vendor:ciscomodel:ip phone 8841scope:ltversion:14.3\(1\)

Trust: 1.0

vendor:ciscomodel:ip phone 8851nrscope:ltversion:14.3\(1\)

Trust: 1.0

vendor:ciscomodel:ip conference phone 8831scope:ltversion:14.3\(1\)

Trust: 1.0

vendor:ciscomodel:ip phone 7811scope:ltversion:14.3\(1\)

Trust: 1.0

vendor:ciscomodel:ip phone 8851scope:ltversion:14.3\(1\)

Trust: 1.0

vendor:ciscomodel:ip phone 8811scope:ltversion:14.3\(1\)

Trust: 1.0

vendor:ciscomodel:ip phone 7821scope:ltversion:14.3\(1\)

Trust: 1.0

vendor:ciscomodel:desk phone 9861scope:eqversion:3.1\(1\)

Trust: 1.0

vendor:ciscomodel:desk phonescope:eqversion:9800

Trust: 0.6

vendor:ciscomodel:ip phonescope:eqversion:7800

Trust: 0.6

vendor:ciscomodel:ip phonescope:eqversion:8800

Trust: 0.6

vendor:ciscomodel:video phonescope:eqversion:8875

Trust: 0.6

sources: CNVD: CNVD-2025-05983 // NVD: CVE-2024-20445

CVSS

SEVERITY

CVSSV2

CVSSV3

psirt@cisco.com: CVE-2024-20445
value: MEDIUM

Trust: 1.0

CNVD: CNVD-2025-05983
value: MEDIUM

Trust: 0.6

CNVD: CNVD-2025-05983
severity: MEDIUM
baseScore: 5.0
vectorString: AV:N/AC:L/AU:N/C:P/I:N/A:N
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: NONE
availabilityImpact: NONE
exploitabilityScore: 10.0
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.6

psirt@cisco.com: CVE-2024-20445
baseSeverity: MEDIUM
baseScore: 5.3
vectorString: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
attackVector: NETWORK
attackComplexity: LOW
privilegesRequired: NONE
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: LOW
integrityImpact: NONE
availabilityImpact: NONE
exploitabilityScore: 3.9
impactScore: 1.4
version: 3.1

Trust: 1.0

sources: CNVD: CNVD-2025-05983 // NVD: CVE-2024-20445

PROBLEMTYPE DATA

problemtype:CWE-200

Trust: 1.0

sources: NVD: CVE-2024-20445

PATCH

title:Patch for Cisco IP Phone Information Disclosure Vulnerabilityurl:https://www.cnvd.org.cn/patchInfo/show/673241

Trust: 0.6

sources: CNVD: CNVD-2025-05983

EXTERNAL IDS

db:NVDid:CVE-2024-20445

Trust: 1.6

db:CNVDid:CNVD-2025-05983

Trust: 0.6

sources: CNVD: CNVD-2025-05983 // NVD: CVE-2024-20445

REFERENCES

url:https://sec.cloudapps.cisco.com/security/center/content/ciscosecurityadvisory/cisco-sa-phone-infodisc-sbyqqvbg

Trust: 1.0

url:https://nvd.nist.gov/vuln/detail/cve-2024-20445

Trust: 0.6

sources: CNVD: CNVD-2025-05983 // NVD: CVE-2024-20445

SOURCES

db:CNVDid:CNVD-2025-05983
db:NVDid:CVE-2024-20445

LAST UPDATE DATE

2026-01-14T23:26:48.492000+00:00


SOURCES UPDATE DATE

db:CNVDid:CNVD-2025-05983date:2025-03-27T00:00:00
db:NVDid:CVE-2024-20445date:2026-01-05T14:57:31.500

SOURCES RELEASE DATE

db:CNVDid:CNVD-2025-05983date:2025-03-25T00:00:00
db:NVDid:CVE-2024-20445date:2024-11-06T17:15:14.830