2.1
CVSSv2

CVE-2022-20660

Published: 14/01/2022 Updated: 07/11/2023
CVSS v2 Base Score: 2.1 | Impact Score: 2.9 | Exploitability Score: 3.9
CVSS v3 Base Score: 4.6 | Impact Score: 3.6 | Exploitability Score: 0.9
VMScore: 188
Vector: AV:L/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

A vulnerability in the information storage architecture of several Cisco IP Phone models could allow an unauthenticated, physical malicious user to obtain confidential information from an affected device. This vulnerability is due to unencrypted storage of confidential information on an affected device. An attacker could exploit this vulnerability by physically extracting and accessing one of the flash memory chips. A successful exploit could allow the malicious user to obtain confidential information from the device, which could be used for subsequent attacks.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

cisco ip conference phone 7832 firmware

cisco ip conference phone 8832 firmware

cisco ip phone 7811 firmware

cisco ip phone 7821 firmware

cisco ip phone 7841 firmware

cisco ip phone 7861 firmware

cisco ip phone 8811 firmware

cisco ip phone 8841 firmware

cisco ip phone 8845 firmware

cisco ip phone 8851 firmware

cisco ip phone 8861 firmware

cisco ip phone 8865 firmware

cisco unified ip conference phone 8831 firmware -

cisco unified ip conference phone 8831 for third-party call control firmware -

cisco unified ip phone 7945g firmware -

cisco unified ip phone 7965g firmware -

cisco unified ip phone 7975g firmware -

cisco unified sip phone 3905 firmware

cisco wireless ip phone 8821 firmware

cisco wireless ip phone 8821-ex firmware

Vendor Advisories

A vulnerability in the information storage architecture of several Cisco IP Phone models could allow an unauthenticated, physical attacker to obtain confidential information from an affected device This vulnerability is due to unencrypted storage of confidential information on an affected device An attacker could exploit this vulnerability by phy ...

Exploits

Cisco IP Phone Series 78x1, 88x5, 88x1, 7832, 8832, 8821 and 3905 suffer from an insecure password storage vulnerability ...

Mailing Lists

SEC Consult Vulnerability Lab Security Advisory < 20220113-0 > ======================================================================= title: Cleartext Storage of Phone Password product: Cisco IP Phone Series 78x1, 88x5, 88x1, 7832, 8832, 8821 and 3905 vulnerable version: Firmware <1411 ...