ID

VAR-202411-2670


CVE

CVE-2024-20445


TITLE

Cisco IP Phone Information Disclosure Vulnerability

Trust: 0.6

sources: CNVD: CNVD-2025-05983

DESCRIPTION

A vulnerability in the web UI of Cisco Desk Phone 9800 Series, Cisco IP Phone 7800 and 8800 Series, and Cisco Video Phone 8875 could allow an unauthenticated, remote attacker to access sensitive information on an affected device. This vulnerability is due to improper storage of sensitive information within the web UI of Session Initiation Protocol (SIP)-based phone loads. An attacker could exploit this vulnerability by browsing to the IP address of a device that has Web Access enabled. A successful exploit could allow the attacker to access sensitive information, including incoming and outgoing call records. Note: Web Access is disabled by default. It is an IP phone that provides calling functions

Trust: 1.44

sources: NVD: CVE-2024-20445 // CNVD: CNVD-2025-05983

IOT TAXONOMY

category:['IoT']sub_category: -

Trust: 0.6

sources: CNVD: CNVD-2025-05983

AFFECTED PRODUCTS

vendor:ciscomodel:desk phonescope:eqversion:9800

Trust: 0.6

vendor:ciscomodel:ip phonescope:eqversion:7800

Trust: 0.6

vendor:ciscomodel:ip phonescope:eqversion:8800

Trust: 0.6

vendor:ciscomodel:video phonescope:eqversion:8875

Trust: 0.6

sources: CNVD: CNVD-2025-05983

CVSS

SEVERITY

CVSSV2

CVSSV3

ykramarz@cisco.com: CVE-2024-20445
value: MEDIUM

Trust: 1.0

CNVD: CNVD-2025-05983
value: MEDIUM

Trust: 0.6

CNVD: CNVD-2025-05983
severity: MEDIUM
baseScore: 5.0
vectorString: AV:N/AC:L/AU:N/C:P/I:N/A:N
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: NONE
availabilityImpact: NONE
exploitabilityScore: 10.0
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.6

ykramarz@cisco.com: CVE-2024-20445
baseSeverity: MEDIUM
baseScore: 5.3
vectorString: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
attackVector: NETWORK
attackComplexity: LOW
privilegesRequired: NONE
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: LOW
integrityImpact: NONE
availabilityImpact: NONE
exploitabilityScore: 3.9
impactScore: 1.4
version: 3.1

Trust: 1.0

sources: CNVD: CNVD-2025-05983 // NVD: CVE-2024-20445

PROBLEMTYPE DATA

problemtype:CWE-200

Trust: 1.0

sources: NVD: CVE-2024-20445

PATCH

title:Patch for Cisco IP Phone Information Disclosure Vulnerabilityurl:https://www.cnvd.org.cn/patchInfo/show/673241

Trust: 0.6

sources: CNVD: CNVD-2025-05983

EXTERNAL IDS

db:NVDid:CVE-2024-20445

Trust: 1.6

db:CNVDid:CNVD-2025-05983

Trust: 0.6

sources: CNVD: CNVD-2025-05983 // NVD: CVE-2024-20445

REFERENCES

url:https://sec.cloudapps.cisco.com/security/center/content/ciscosecurityadvisory/cisco-sa-phone-infodisc-sbyqqvbg

Trust: 1.0

url:https://nvd.nist.gov/vuln/detail/cve-2024-20445

Trust: 0.6

sources: CNVD: CNVD-2025-05983 // NVD: CVE-2024-20445

SOURCES

db:CNVDid:CNVD-2025-05983
db:NVDid:CVE-2024-20445

LAST UPDATE DATE

2025-03-30T22:57:47.340000+00:00


SOURCES UPDATE DATE

db:CNVDid:CNVD-2025-05983date:2025-03-27T00:00:00
db:NVDid:CVE-2024-20445date:2024-11-06T18:17:17.287

SOURCES RELEASE DATE

db:CNVDid:CNVD-2025-05983date:2025-03-25T00:00:00
db:NVDid:CVE-2024-20445date:2024-11-06T17:15:14.830