Cisco Family Security Update Advisory

Overview

 

We have released updates to fix vulnerabilities in the Cisco family of products. users of affected versions are advised to update to the latest version.

 

Affected Products

 

  • IP Phone 6800 with Multiplatform Firmware
  • IP Phone 7800 with Multiplatform Firmware
  • IP Phone 8800 with Multiplatform Firmware
  • Video Phone 8875 in Multiplatform Mode

 

Resolved Vulnerabilities

 

Denial of Service Vulnerability Due to a Vulnerability in the Web-based Management Interface in Cisco IP Phone Firmware (CVE-2024-20376)

Information disclosure vulnerability due to a vulnerability in the web-based management interface in Cisco IP Phone Firmware (CVE-2024-20378)

 

Vulnerability Patches

 

Vulnerability Patches have been made available in the latest updates. Please follow the instructions on the Referenced Sites to update to the latest Vulnerability Patches version.

 

Cisco Multiplatform Firmware 12.0.4SR1 version

Cisco PhoneOS 2.3.1.0101 version

 

Referenced Sites

 

[1] Cisco IP Phone 6800, 7800, and 8800 Series with Multiplatform Firmware Vulnerabilities

https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ipphone-multi-vulns-cXAhCvS