ID

VAR-202509-1174


CVE

CVE-2025-20336


DESCRIPTION

A vulnerability in the directory permissions of Cisco Desk Phone 9800 Series, Cisco IP Phone 7800 and 8800 Series, and Cisco Video Phone 8875 could allow an unauthenticated, remote attacker to access sensitive information on an affected device. This vulnerability exists because the product exposes sensitive information to an actor that is not explicitly authorized to have access to that information. An attacker could exploit this vulnerability by sending a crafted packet to the IP address of a device that has Web Access enabled. A successful exploit could allow the attacker to access sensitive information from the device. Note: To exploit this vulnerability, Web Access must be enabled on the phone. Web Access is disabled by default.

Trust: 1.0

sources: NVD: CVE-2025-20336

AFFECTED PRODUCTS

vendor:ciscomodel:ip phone 8851scope:ltversion:14.3\(1\)

Trust: 1.0

vendor:ciscomodel:video phone 8875scope:gteversion:3.0\(1\)

Trust: 1.0

vendor:ciscomodel:desk phone 9841scope:ltversion:3.3\(1\)

Trust: 1.0

vendor:ciscomodel:ip phone 8861scope:eqversion:14.3\(1\)

Trust: 1.0

vendor:ciscomodel:ip phone 7841scope:ltversion:14.3\(1\)

Trust: 1.0

vendor:ciscomodel:ip phone 8865scope:ltversion:14.3\(1\)

Trust: 1.0

vendor:ciscomodel:ip phone 7861scope:eqversion:14.3\(1\)

Trust: 1.0

vendor:ciscomodel:desk phone 9851scope:ltversion:3.3\(1\)

Trust: 1.0

vendor:ciscomodel:desk phone 9841scope:gteversion:3.0\(1\)

Trust: 1.0

vendor:ciscomodel:ip phone 8821scope:eqversion:11.0\(6\)

Trust: 1.0

vendor:ciscomodel:video phone 8875scope:eqversion:2.3\(1\)

Trust: 1.0

vendor:ciscomodel:ip phone 8841scope:eqversion:14.3\(1\)

Trust: 1.0

vendor:ciscomodel:ip phone 8845scope:ltversion:14.3\(1\)

Trust: 1.0

vendor:ciscomodel:video phone 8875scope:ltversion:2.3\(1\)

Trust: 1.0

vendor:ciscomodel:desk phone 9851scope:gteversion:3.0\(1\)

Trust: 1.0

vendor:ciscomodel:desk phone 9861scope:ltversion:3.3\(1\)

Trust: 1.0

vendor:ciscomodel:ip phone 8851nrscope:eqversion:14.3\(1\)

Trust: 1.0

vendor:ciscomodel:desk phone 9871scope:ltversion:3.3\(1\)

Trust: 1.0

vendor:ciscomodel:ip phone 7811scope:eqversion:14.3\(1\)

Trust: 1.0

vendor:ciscomodel:ip phone 8851scope:eqversion:14.3\(1\)

Trust: 1.0

vendor:ciscomodel:desk phone 9861scope:gteversion:3.0\(1\)

Trust: 1.0

vendor:ciscomodel:ip phone 8861scope:ltversion:14.3\(1\)

Trust: 1.0

vendor:ciscomodel:ip phone 8811scope:eqversion:14.3\(1\)

Trust: 1.0

vendor:ciscomodel:ip phone 7861scope:ltversion:14.3\(1\)

Trust: 1.0

vendor:ciscomodel:video phone 8875scope:ltversion:3.3\(1\)

Trust: 1.0

vendor:ciscomodel:ip phone 8821scope:ltversion:11.0\(6\)

Trust: 1.0

vendor:ciscomodel:desk phone 9871scope:gteversion:3.0\(1\)

Trust: 1.0

vendor:ciscomodel:ip phone 8841scope:ltversion:14.3\(1\)

Trust: 1.0

vendor:ciscomodel:ip phone 7841scope:eqversion:14.3\(1\)

Trust: 1.0

vendor:ciscomodel:ip phone 8851nrscope:ltversion:14.3\(1\)

Trust: 1.0

vendor:ciscomodel:ip phone 8865scope:eqversion:14.3\(1\)

Trust: 1.0

vendor:ciscomodel:ip phone 7811scope:ltversion:14.3\(1\)

Trust: 1.0

vendor:ciscomodel:ip phone 7821scope:eqversion:14.3\(1\)

Trust: 1.0

vendor:ciscomodel:ip phone 8811scope:ltversion:14.3\(1\)

Trust: 1.0

vendor:ciscomodel:ip phone 7821scope:ltversion:14.3\(1\)

Trust: 1.0

vendor:ciscomodel:ip phone 8845scope:eqversion:14.3\(1\)

Trust: 1.0

sources: NVD: CVE-2025-20336

CVSS

SEVERITY

CVSSV2

CVSSV3

psirt@cisco.com: CVE-2025-20336
value: MEDIUM

Trust: 1.0

nvd@nist.gov: CVE-2025-20336
value: HIGH

Trust: 1.0

psirt@cisco.com: CVE-2025-20336
baseSeverity: MEDIUM
baseScore: 5.3
vectorString: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
attackVector: NETWORK
attackComplexity: LOW
privilegesRequired: NONE
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: LOW
integrityImpact: NONE
availabilityImpact: NONE
exploitabilityScore: 3.9
impactScore: 1.4
version: 3.1

Trust: 1.0

nvd@nist.gov: CVE-2025-20336
baseSeverity: HIGH
baseScore: 7.5
vectorString: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
attackVector: NETWORK
attackComplexity: LOW
privilegesRequired: NONE
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: HIGH
integrityImpact: NONE
availabilityImpact: NONE
exploitabilityScore: 3.9
impactScore: 3.6
version: 3.1

Trust: 1.0

sources: NVD: CVE-2025-20336 // NVD: CVE-2025-20336

PROBLEMTYPE DATA

problemtype:CWE-200

Trust: 1.0

sources: NVD: CVE-2025-20336

EXTERNAL IDS

db:NVDid:CVE-2025-20336

Trust: 1.0

sources: NVD: CVE-2025-20336

REFERENCES

url:https://sec.cloudapps.cisco.com/security/center/content/ciscosecurityadvisory/cisco-sa-phone-write-g3kcc5df

Trust: 1.0

sources: NVD: CVE-2025-20336

SOURCES

db:NVDid:CVE-2025-20336

LAST UPDATE DATE

2026-01-14T23:52:14.007000+00:00


SOURCES UPDATE DATE

db:NVDid:CVE-2025-20336date:2026-01-05T14:49:30.253

SOURCES RELEASE DATE

db:NVDid:CVE-2025-20336date:2025-09-03T18:15:34.637