Cisco IP Phone 6800, 7800, and 8800 Series with Multiplatform Firmware Cross-Site Request Forgery Vulnerability
false
Cisco IP Phone 6800, 7800, and 8800 Series with Multiplatform Firmware Cross-Site Request Forgery Vulnerability
Cisco IP Phone 6800, 7800, and 8800 Series with Multiplatform Firmware Cross-Site Request Forgery Vulnerability
Overview
A vulnerability in the web-based management interface of Cisco IP Phone 6800, 7800, and 8800 Series with Multiplatform Firmware could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack against a user of the web-based management interface of an affected system.
IP Phone 6800, 7800, and 8800 Multiplatform Firmware
Cisco Multiplatform Firmware Release
First Fixed Release
11.3 and earlier
Affected, please migrate to a fixed release.
12.0
Not vulnerable.
Video Phone 8875
Cisco PhoneOS Release
First Fixed Release
1.0
Affected, please migrate to a fixed release.
2.0
Not vulnerable.
2.1
Not vulnerable.
Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability.
Full description of the vulnerability is available on the following link: