Vulnerabilities > Cisco > IP Conference Phone 8832 Firmware > 10.3.1

DATE CVE VULNERABILITY TITLE RISK
2022-01-14 CVE-2022-20660 Cleartext Storage of Sensitive Information vulnerability in Cisco products
A vulnerability in the information storage architecture of several Cisco IP Phone models could allow an unauthenticated, physical attacker to obtain confidential information from an affected device.
low complexity
cisco CWE-312
4.6
2021-10-06 CVE-2021-34711 Path Traversal vulnerability in Cisco products
A vulnerability in the debug shell of Cisco IP Phone software could allow an authenticated, local attacker to read any file on the device file system.
local
low complexity
cisco CWE-22
5.5
2021-05-11 CVE-2020-26141 Improper Validation of Integrity Check Value vulnerability in multiple products
An issue was discovered in the ALFA Windows 10 driver 6.1316.1209 for AWUS036H.
low complexity
alfa cisco siemens CWE-354
3.3
2020-02-05 CVE-2020-3111 Improper Input Validation vulnerability in Cisco products
A vulnerability in the Cisco Discovery Protocol implementation for the Cisco IP Phone could allow an unauthenticated, adjacent attacker to remotely execute code with root privileges or cause a reload of an affected IP phone.
low complexity
cisco CWE-20
8.3
2019-03-22 CVE-2019-1765 Path Traversal vulnerability in Cisco products
A vulnerability in the web-based management interface of Session Initiation Protocol (SIP) Software for Cisco IP Phone 8800 Series could allow an authenticated, remote attacker to write arbitrary files to the filesystem.
network
low complexity
cisco CWE-22
4.0
2019-03-22 CVE-2019-1764 Cross-Site Request Forgery (CSRF) vulnerability in Cisco products
A vulnerability in the web-based management interface of Session Initiation Protocol (SIP) Software for Cisco IP Phone 8800 Series could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack.
network
cisco CWE-352
6.8
2019-03-22 CVE-2019-1763 Improper Access Control vulnerability in Cisco products
A vulnerability in the web-based management interface of Session Initiation Protocol (SIP) Software for Cisco IP Phone 8800 Series could allow an unauthenticated, remote attacker to bypass authorization, access critical services, and cause a denial of service (DoS) condition.
network
low complexity
cisco CWE-284
5.0
2019-02-21 CVE-2019-1684 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Cisco products
A vulnerability in the Cisco Discovery Protocol or Link Layer Discovery Protocol (LLDP) implementation for the Cisco IP Phone 7800 and 8800 Series could allow an unauthenticated, adjacent attacker to cause an affected phone to reload unexpectedly, resulting in a temporary denial of service (DoS) condition.
low complexity
cisco CWE-119
6.1