CVE-2023-20018
📛 CVE Title
CVE-2023-20018
Description
A vulnerability in the web-based management interface of Cisco IP Phone 7800 and 8800 Series Phones could allow an unauthenticated, remote attacker to bypass authentication on an affected device. This vulnerability is due to insufficient validation of user-supplied input. An attacker could exploit this vulnerability by sending a crafted request to the web-based management interface. A successful exploit could allow the attacker to access certain parts of the web interface that would normally require authentication.
Overview
- State
- PUBLISHED
- Assigner (CNA)
- cisco
- CVSS severity
- HIGH
- CVSS score
- 8.6 / 10
- CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H- Effective score
- 8.6 / 10 HIGH source: CNA overview
- CWE(s)
-
CWE-288 - Reserved
- 2022-10-27
- Published
- 2023-01-19 02:35 UTC
- Last updated
- 2024-08-02 10:57 UTC
- Source
- https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2023/20xxx/CVE-2023-20018.json
- Linked Threat
- CVE-2023-20018 — CVE-2023-20018
European Union Vulnerability Database ENISA EUVD
ENISA's official EU repository for curated vulnerability intelligence. Carries a separate identifier (EUVD-YYYY-NNNN) and frequently exposes an earlier-published description + CVSS than NVD does.
- EUVD ID
-
EUVD-2023-24197 - Assigner
- cisco
- Published
- Jan 19, 2023, 1:35:41 AM
- Updated
- Aug 2, 2024, 8:57:35 AM
- EUVD base score (CVSS 3.1)
-
8.6 / 10
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H - EUVD-reported EPSS
- 0.3800
- Vendors
- Cisco
- Products
-
Cisco Session Initiation Protocol (SIP) Software (11.0(3)SR5)Cisco Session Initiation Protocol (SIP) Software (10.2(1))Cisco Session Initiation Protocol (SIP) Software (10.3(1.11) 3rd Party)Cisco Session Initiation Protocol (SIP) Software (11.0(3)SR3)Cisco Session Initiation Protocol (SIP) Software (10.3(1)SR4)Cisco Session Initiation Protocol (SIP) Software (14.0(1)SR1)Cisco Session Initiation Protocol (SIP) Software (10.2(2))Cisco Session Initiation Protocol (SIP) Software (11.0(4))Cisco Session Initiation Protocol (SIP) Software (10.3(1)SR5)Cisco Session Initiation Protocol (SIP) Software (11.0(3)SR6)Cisco Session Initiation Protocol (SIP) Software (11.0(6)SR2)Cisco Session Initiation Protocol (SIP) Software (11.0(3)SR1)Cisco Session Initiation Protocol (SIP) Software (12.8(1)SR2)Cisco Session Initiation Protocol (SIP) Software (12.5(1)SR1)Cisco Session Initiation Protocol (SIP) Software (11.5(1)SR1)Cisco Session Initiation Protocol (SIP) Software (11.0(5)SR1)Cisco Session Initiation Protocol (SIP) Software (10.2(1)SR1)Cisco Session Initiation Protocol (SIP) Software (12.7(1))Cisco Session Initiation Protocol (SIP) Software (10.1(1)SR2)Cisco Session Initiation Protocol (SIP) Software (11.0(6))Cisco Session Initiation Protocol (SIP) Software (10.1(1.9))Cisco Session Initiation Protocol (SIP) Software (12.0(1)SR3)Cisco Session Initiation Protocol (SIP) Software (10.3(1)SR2)Cisco Session Initiation Protocol (SIP) Software (12.0(1)SR1)Cisco Session Initiation Protocol (SIP) Software (14.0(1)SR2)Cisco Session Initiation Protocol (SIP) Software (11.0(3))Cisco Session Initiation Protocol (SIP) Software (11.5(1))Cisco Session Initiation Protocol (SIP) Software (11.0(0.7) MPP)Cisco Session Initiation Protocol (SIP) Software (11.0(5))Cisco Session Initiation Protocol (SIP) Software (11.0(1))Cisco Session Initiation Protocol (SIP) Software (11.0(3)SR2)Cisco Session Initiation Protocol (SIP) Software (11.0(5)SR2)Cisco Session Initiation Protocol (SIP) Software (12.6(1))Cisco Session Initiation Protocol (SIP) Software (9.3(4)SR3 3rd Party)Cisco Session Initiation Protocol (SIP) Software (12.6(1)SR1)Cisco Session Initiation Protocol (SIP) Software (11.0(6)SR1)Cisco Session Initiation Protocol (SIP) Software (10.3(1)SR1)Cisco Session Initiation Protocol (SIP) Software (9.3(4)SR2 3rd Party)Cisco Session Initiation Protocol (SIP) Software (11.0(2)SR1)Cisco Session Initiation Protocol (SIP) Software (11.0(4)SR1)Cisco Session Initiation Protocol (SIP) Software (10.3(1)SR4b)Cisco Session Initiation Protocol (SIP) Software (10.3(2))Cisco Session Initiation Protocol (SIP) Software (11-0-1MSR1-1)Cisco Session Initiation Protocol (SIP) Software (14.0(1)SR3)Cisco Session Initiation Protocol (SIP) Software (12.5(1)SR3)Cisco Session Initiation Protocol (SIP) Software (11.0(5)SR3)Cisco Session Initiation Protocol (SIP) Software (12.0(1)SR2)Cisco Session Initiation Protocol (SIP) Software (10.3(1)SR3)Cisco Session Initiation Protocol (SIP) Software (9.3(4) 3rd Party)Cisco Session Initiation Protocol (SIP) Software (11.0(3)SR4)Cisco Session Initiation Protocol (SIP) Software (10.4(1)SR2 3rd Party)Cisco Session Initiation Protocol (SIP) Software (11.0(2))Cisco Session Initiation Protocol (SIP) Software (10.4(1) 3rd Party)Cisco Session Initiation Protocol (SIP) Software (11.0(4)SR2)Cisco Session Initiation Protocol (SIP) Software (12.1(1))Cisco Session Initiation Protocol (SIP) Software (14.0(1))Cisco Session Initiation Protocol (SIP) Software (10.3(1)SR6)Cisco Session Initiation Protocol (SIP) Software (11.7(1))Cisco Session Initiation Protocol (SIP) Software (12.0(1))Cisco Session Initiation Protocol (SIP) Software (10.3(1.9) 3rd Party)Cisco Session Initiation Protocol (SIP) Software (12.8(1))Cisco Session Initiation Protocol (SIP) Software (12.1(1)SR1)Cisco Session Initiation Protocol (SIP) Software (9.3(4)SR1 3rd Party)Cisco Session Initiation Protocol (SIP) Software (10.1(1)SR1)Cisco Session Initiation Protocol (SIP) Software (14.1(1)SR1)Cisco Session Initiation Protocol (SIP) Software (12.5(1))Cisco Session Initiation Protocol (SIP) Software (11.0(1) MPP)Cisco Session Initiation Protocol (SIP) Software (11.0(2)SR2)Cisco Session Initiation Protocol (SIP) Software (14.1(1))Cisco Session Initiation Protocol (SIP) Software (12.5(1)SR2)Cisco Session Initiation Protocol (SIP) Software (10.3(1))Cisco Session Initiation Protocol (SIP) Software (12.8(1)SR1)Cisco Session Initiation Protocol (SIP) Software (12.7(1)SR1)Cisco Session Initiation Protocol (SIP) Software (10.3(1)SR7)Cisco Session Initiation Protocol (SIP) Software (11.0(4)SR3)
- Aliases
-
GHSA-jc6w-v2gh-gqx3
ENISA description: A vulnerability in the web-based management interface of Cisco IP Phone 7800 and 8800 Series Phones could allow an unauthenticated, remote attacker to bypass authentication on an affected device. This vulnerability is due to insufficient validation of user-supplied input. An attacker could exploit this vulnerability by sending a crafted request to the web-based management interface. A successful exploit could allow the attacker to access certain parts of the web interface that would normally require authentication.
Affected products (1)
| Vendor | Product | Versions | Platforms |
|---|---|---|---|
| Cisco | Cisco Session Initiation Protocol (SIP) Software |
9.3(4) 3rd Party (affected),
9.3(4)SR3 3rd Party (affected),
9.3(4)SR1 3rd Party (affected),
9.3(4)SR2 3rd Party (affected),
11.0(3)SR3 (affected),
11.0(2)SR1 (affected),
11.5(1) (affected),
11.0(5)SR2 (affected),
11.0(2) (affected),
11.7(1) (affected),
11.0(4)SR3 (affected),
11.0(0.7) MPP (affected),
11.0(4)SR2 (affected),
11.0(3)SR5 (affected),
11.0(3)SR6 (affected),
11.0(3) (affected),
11.0(4)SR1 (affected),
11.0(1) MPP (affected),
11.0(4) (affected),
11.0(3)SR4 (affected),
11.0(5) (affected),
11.0(3)SR1 (affected),
11.0(5)SR1 (affected),
11.0(3)SR2 (affected),
11.0(2)SR2 (affected),
11.0(1) (affected),
11.5(1)SR1 (affected),
11-0-1MSR1-1 (affected),
10.4(1) 3rd Party (affected),
10.3(1.11) 3rd Party (affected),
10.2(2) (affected),
10.2(1)SR1 (affected),
10.1(1.9) (affected),
10.1(1)SR2 (affected),
10.2(1) (affected),
10.1(1)SR1 (affected),
10.4(1)SR2 3rd Party (affected),
10.3(1) (affected),
10.3(1)SR4b (affected),
10.3(1)SR5 (affected),
10.3(1.9) 3rd Party (affected),
10.3(2) (affected),
10.3(1)SR4 (affected),
10.3(1)SR2 (affected),
10.3(1)SR3 (affected),
10.3(1)SR1 (affected),
12.6(1) (affected),
12.1(1) (affected),
12.5(1)SR1 (affected),
12.5(1)SR2 (affected),
12.5(1) (affected),
12.5(1)SR3 (affected),
12.6(1)SR1 (affected),
12.7(1) (affected),
12.1(1)SR1 (affected),
12.0(1) (affected),
12.0(1)SR2 (affected),
12.0(1)SR1 (affected),
12.0(1)SR3 (affected),
12.8(1) (affected),
12.8(1)SR1 (affected),
12.8(1)SR2 (affected),
11.0(5)SR3 (affected),
11.0(6) (affected),
11.0(6)SR1 (affected),
11.0(6)SR2 (affected),
10.3(1)SR6 (affected),
10.3(1)SR7 (affected),
12.7(1)SR1 (affected),
14.0(1)SR1 (affected),
14.0(1) (affected),
14.0(1)SR2 (affected),
14.0(1)SR3 (affected),
14.1(1) (affected),
14.1(1)SR1 (affected)
|
— |
Vendor references (1)
References embedded in the original CVE record by the assigning CNA.
Web references (0)
DuckDuckGo results ranked by threat-intel / vendor advisory domains. Generated by the 🔎 Find references (web) button above — same flow as the Remediations search.
No web references attached yet.
Remediations (16)
Remediations are stored against the linked Threat row; the list below is deduplicated across both pages.
-
web:tuxcare.com
It includes discovering vulnerabilities, evaluating their potential impact, prioritizing remediation efforts (including patching), and confirming the fixes. Patch Management Patch management, on the other hand, is the act of applying the necessary updates to fix known vulnerabilities. It's a critical component of vulnerability management.
2026-06-03 09:31 UTC -
web:portal.msrc.microsoft.com
The Microsoft Security Response Center (MSRC) investigates all reports of security vulnerabilities affecting Microsoft products and services, and provides the information here as part of the ongoing effort to help you manage security risks and help keep your systems protected.
2026-06-03 09:31 UTC -
web:support.microsoft.com
For information about Windows update terminology, see types of Windows updates and the monthly quality update types. To find an overview of Windows 11, version 23H2, see its update history page. This month's video is ready for you on Windows 11, version 24H2. Be sure to follow @WindowsUpdate to find out when new content is published to the Windows release health dashboard.
2026-06-03 09:31 UTC -
web:support.microsoft.com
This out-of-band update for Windows 11, version 25H2 and 24H2 (KB5085518) includes fixes and improvements. To learn more about differences between security updates, optional non-security preview updates, out-of-band (OOB) updates, and continuous innovation, see Windows monthly updates explained. For information on Windows update terminology, see the different types of Windows software updates ...
2026-06-03 09:31 UTC -
web:support.servicenow.com
Overview The advisories below document publicly disclosed Common Vulnerabilities and Exposures ( CVEs ) in the Now Platform by ServiceNow. Because ServiceNow uses various methods to communicate vulnerability information, patches, and other fixes, customers should review family, security patch , and hotfix release notes, which are available at https://docs.servicenow.com, for a complete list of ...
2026-06-03 09:31 UTC -
web:techcommunity.microsoft.com
Windows Autopatch is enabling hotpatch security updates by default to help secure devices even faster. This change in default behavior comes to all eligible [i] devices in Microsoft Intune and those accessing the service via Microsoft Graph API starting with the May 2026 Windows security update. Applying security fixes without waiting for a restart can get organizations to 90% compliance in ...
2026-06-03 09:31 UTC -
web:www.oracle.com
This Critical Patch Update contains 481 new security patches across the product families listed below. Please note that an MOS note summarizing the content of this Critical Patch Update and other Oracle Software Security Assurance activities is located at April 2026 Critical Patch Update: Executive Summary and Analysis.
2026-05-22 05:41 UTC -
web:www.pcworld.com
This month's Patch Tuesday includes an actively exploited Office zero-day vulnerability and several critical RCE bugs in Windows and Remote Desktop.
2026-05-22 05:41 UTC -
web:www.securityweek.com
Microsoft has announced mitigations for CVE -2026-45585, a BitLocker bypass triggered via FsTx in Windows Recovery.
2026-05-22 05:41 UTC -
web:access.redhat.com
Learn about our open source products, services, and company. You are here
2026-05-22 05:41 UTC -
web:zecurit.com
Get the complete breakdown of Microsoft's May 2026 Patch Tuesday. We analyze the latest security updates and all critical CVEs .
2026-05-22 05:41 UTC -
web:blog.qualys.com
Review Microsoft and Adobe's December 2024 Patch Tuesday updates, addressing critical vulnerabilities and key fixes for enhanced security protection.
2026-05-22 05:41 UTC -
web:cybersecuritynews.com
Microsoft's May 2026 Patch Tuesday lands with a heavy enterprise focus, fixing 120 vulnerabilities across Windows, Office, Azure, developer tools, and Microsoft 365 apps, including 29 remote code execution (RCE) flaws rated Critical.
2026-05-22 05:41 UTC -
web:krebsonsecurity.com
Microsoft Corp. today issued security updates to fix more than 80 vulnerabilities in its Windows operating systems and software. There are no known "zero-day" or actively exploited vulnerabilities ...
2026-05-22 05:41 UTC -
web:portal.msrc.microsoft.com
The Security Update Guide provides information on the latest Microsoft security updates, helping users understand and address potential vulnerabilities effectively.
2026-05-22 05:41 UTC -
web:www.bleepingcomputer.com
Today is Microsoft's March 2026 Patch Tuesday with security updates for 79 flaws, including 2 publicly disclosed zero-day vulnerabilities.
2026-05-22 05:41 UTC
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.
Raw JSON
The full cvelistV5 record. Download as CVE-2023-20018.json.
{
"containers": {
"adp": [
{
"providerMetadata": {
"dateUpdated": "2024-08-02T08:57:35.086Z",
"orgId": "af854a3a-2127-422b-91ae-364da2661108",
"shortName": "CVE"
},
"references": [
{
"name": "cisco-sa-ip-phone-auth-bypass-pSqxZRPR",
"tags": [
"x_transferred"
],
"url": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ip-phone-auth-bypass-pSqxZRPR"
}
],
"title": "CVE Program Container"
}
],
"cna": {
"affected": [
{
"product": "Cisco Session Initiation Protocol (SIP) Software",
"vendor": "Cisco",
"versions": [
{
"status": "affected",
"version": "9.3(4) 3rd Party"
},
{
"status": "affected",
"version": "9.3(4)SR3 3rd Party"
},
{
"status": "affected",
"version": "9.3(4)SR1 3rd Party"
},
{
"status": "affected",
"version": "9.3(4)SR2 3rd Party"
},
{
"status": "affected",
"version": "11.0(3)SR3"
},
{
"status": "affected",
"version": "11.0(2)SR1"
},
{
"status": "affected",
"version": "11.5(1)"
},
{
"status": "affected",
"version": "11.0(5)SR2"
},
{
"status": "affected",
"version": "11.0(2)"
},
{
"status": "affected",
"version": "11.7(1)"
},
{
"status": "affected",
"version": "11.0(4)SR3"
},
{
"status": "affected",
"version": "11.0(0.7) MPP"
},
{
"status": "affected",
"version": "11.0(4)SR2"
},
{
"status": "affected",
"version": "11.0(3)SR5"
},
{
"status": "affected",
"version": "11.0(3)SR6"
},
{
"status": "affected",
"version": "11.0(3)"
},
{
"status": "affected",
"version": "11.0(4)SR1"
},
{
"status": "affected",
"version": "11.0(1) MPP"
},
{
"status": "affected",
"version": "11.0(4)"
},
{
"status": "affected",
"version": "11.0(3)SR4"
},
{
"status": "affected",
"version": "11.0(5)"
},
{
"status": "affected",
"version": "11.0(3)SR1"
},
{
"status": "affected",
"version": "11.0(5)SR1"
},
{
"status": "affected",
"version": "11.0(3)SR2"
},
{
"status": "affected",
"version": "11.0(2)SR2"
},
{
"status": "affected",
"version": "11.0(1)"
},
{
"status": "affected",
"version": "11.5(1)SR1"
},
{
"status": "affected",
"version": "11-0-1MSR1-1"
},
{
"status": "affected",
"version": "10.4(1) 3rd Party"
},
{
"status": "affected",
"version": "10.3(1.11) 3rd Party"
},
{
"status": "affected",
"version": "10.2(2)"
},
{
"status": "affected",
"version": "10.2(1)SR1"
},
{
"status": "affected",
"version": "10.1(1.9)"
},
{
"status": "affected",
"version": "10.1(1)SR2"
},
{
"status": "affected",
"version": "10.2(1)"
},
{
"status": "affected",
"version": "10.1(1)SR1"
},
{
"status": "affected",
"version": "10.4(1)SR2 3rd Party"
},
{
"status": "affected",
"version": "10.3(1)"
},
{
"status": "affected",
"version": "10.3(1)SR4b"
},
{
"status": "affected",
"version": "10.3(1)SR5"
},
{
"status": "affected",
"version": "10.3(1.9) 3rd Party"
},
{
"status": "affected",
"version": "10.3(2)"
},
{
"status": "affected",
"version": "10.3(1)SR4"
},
{
"status": "affected",
"version": "10.3(1)SR2"
},
{
"status": "affected",
"version": "10.3(1)SR3"
},
{
"status": "affected",
"version": "10.3(1)SR1"
},
{
"status": "affected",
"version": "12.6(1)"
},
{
"status": "affected",
"version": "12.1(1)"
},
{
"status": "affected",
"version": "12.5(1)SR1"
},
{
"status": "affected",
"version": "12.5(1)SR2"
},
{
"status": "affected",
"version": "12.5(1)"
},
{
"status": "affected",
"version": "12.5(1)SR3"
},
{
"status": "affected",
"version": "12.6(1)SR1"
},
{
"status": "affected",
"version": "12.7(1)"
},
{
"status": "affected",
"version": "12.1(1)SR1"
},
{
"status": "affected",
"version": "12.0(1)"
},
{
"status": "affected",
"version": "12.0(1)SR2"
},
{
"status": "affected",
"version": "12.0(1)SR1"
},
{
"status": "affected",
"version": "12.0(1)SR3"
},
{
"status": "affected",
"version": "12.8(1)"
},
{
"status": "affected",
"version": "12.8(1)SR1"
},
{
"status": "affected",
"version": "12.8(1)SR2"
},
{
"status": "affected",
"version": "11.0(5)SR3"
},
{
"status": "affected",
"version": "11.0(6)"
},
{
"status": "affected",
"version": "11.0(6)SR1"
},
{
"status": "affected",
"version": "11.0(6)SR2"
},
{
"status": "affected",
"version": "10.3(1)SR6"
},
{
"status": "affected",
"version": "10.3(1)SR7"
},
{
"status": "affected",
"version": "12.7(1)SR1"
},
{
"status": "affected",
"version": "14.0(1)SR1"
},
{
"status": "affected",
"version": "14.0(1)"
},
{
"status": "affected",
"version": "14.0(1)SR2"
},
{
"status": "affected",
"version": "14.0(1)SR3"
},
{
"status": "affected",
"version": "14.1(1)"
},
{
"status": "affected",
"version": "14.1(1)SR1"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "A vulnerability in the web-based management interface of Cisco IP Phone 7800 and 8800 Series Phones could allow an unauthenticated, remote attacker to bypass authentication on an affected device.\r\n\r This vulnerability is due to insufficient validation of user-supplied input. An attacker could exploit this vulnerability by sending a crafted request to the web-based management interface. A successful exploit could allow the attacker to access certain parts of the web interface that would normally require authentication."
}
],
"exploits": [
{
"lang": "en",
"value": "The Cisco PSIRT is not aware of any public announcements or malicious use of the vulnerability that is described in this advisory."
}
],
"metrics": [
{
"cvssV3_1": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "HIGH",
"baseScore": 8.6,
"baseSeverity": "HIGH",
"confidentialityImpact": "LOW",
"integrityImpact": "LOW",
"privilegesRequired": "NONE",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H",
"version": "3.1"
},
"format": "cvssV3_1"
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-288",
"description": "Authentication Bypass Using an Alternate Path or Channel",
"lang": "en",
"type": "cwe"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2024-01-25T16:57:31.975Z",
"orgId": "d1c1063e-7a18-46af-9102-31f8928bc633",
"shortName": "cisco"
},
"references": [
{
"name": "cisco-sa-ip-phone-auth-bypass-pSqxZRPR",
"url": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ip-phone-auth-bypass-pSqxZRPR"
}
],
"source": {
"advisory": "cisco-sa-ip-phone-auth-bypass-pSqxZRPR",
"defects": [
"CSCwc37223",
"CSCwc37234"
],
"discovery": "EXTERNAL"
}
}
},
"cveMetadata": {
"assignerOrgId": "d1c1063e-7a18-46af-9102-31f8928bc633",
"assignerShortName": "cisco",
"cveId": "CVE-2023-20018",
"datePublished": "2023-01-19T01:35:41.006Z",
"dateReserved": "2022-10-27T18:47:50.308Z",
"dateUpdated": "2024-08-02T08:57:35.086Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.1"
}