Show filters
45 Total Results
Displaying 1-10 of 45
Sort by:
Attacker Value
Unknown

CVE-2021-1379

Disclosure Date: November 18, 2024 (last updated November 19, 2024)
Multiple vulnerabilities in the Cisco Discovery Protocol and Link Layer Discovery Protocol (LLDP) implementations for Cisco IP Phone Series 68xx/78xx/88xx could allow an unauthenticated, adjacent attacker to execute code remotely or cause a reload of an affected IP phone. These vulnerabilities are due to missing checks when the IP phone processes a Cisco Discovery Protocol or LLDP packet. An attacker could exploit these vulnerabilities by sending a malicious Cisco Discovery Protocol or LLDP packet to the targeted IP phone. A successful exploit could allow the attacker to execute code on the affected IP phone or cause it to reload unexpectedly, resulting in a denial of service (DoS) condition.Note: Cisco Discovery Protocol is a Layer 2 protocol. To exploit these vulnerabilities, an attacker must be in the same broadcast domain as the affected device (Layer 2 adjacent).Cisco has released software updates that address these vulnerabilities. There are no wor…
Attacker Value
Unknown

CVE-2024-20534

Disclosure Date: November 06, 2024 (last updated November 07, 2024)
A vulnerability in the web UI of Cisco Desk Phone 9800 Series, Cisco IP Phone 6800, 7800, and 8800 Series, and Cisco Video Phone 8875 with Cisco Multiplatform Firmware could allow an authenticated, remote attacker to conduct stored cross-site scripting (XSS) attacks against users. This vulnerability exists because the web UI of an affected device does not properly validate user-supplied input. An attacker could exploit this vulnerability by injecting malicious code into specific pages of the interface. A successful exploit could allow the attacker to execute arbitrary script code in the context of the affected interface or access sensitive, browser-based information. Note: To exploit this vulnerability, Web Access must be enabled on the phone and the attacker must have Admin credentials on the device. Web Access is disabled by default.
0
Attacker Value
Unknown

CVE-2024-20533

Disclosure Date: November 06, 2024 (last updated November 07, 2024)
A vulnerability in the web UI of Cisco Desk Phone 9800 Series, Cisco IP Phone 6800, 7800, and 8800 Series, and Cisco Video Phone 8875 with Cisco Multiplatform Firmware could allow an authenticated, remote attacker to conduct stored cross-site scripting (XSS) attacks against users. This vulnerability exists because the web UI of an affected device does not properly validate user-supplied input. An attacker could exploit this vulnerability by injecting malicious code into specific pages of the interface. A successful exploit could allow the attacker to execute arbitrary script code in the context of the affected interface or access sensitive, browser-based information. Note: To exploit this vulnerability, Web Access must be enabled on the phone and the attacker must have Admin credentials on the device. Web Access is disabled by default.
0
Attacker Value
Unknown

CVE-2024-3480

Disclosure Date: May 03, 2024 (last updated January 05, 2025)
An Implicit intent vulnerability was reported in the Motorola framework that could allow an attacker to read telephony-related data.
0
Attacker Value
Unknown

CVE-2024-3479

Disclosure Date: May 03, 2024 (last updated January 05, 2025)
An improper export vulnerability was reported in the Motorola Enterprise MotoDpms Provider (com.motorola.server.enterprise.MotoDpmsProvider) that could allow a local attacker to read local data.
0
Attacker Value
Unknown

CVE-2024-3109

Disclosure Date: May 03, 2024 (last updated January 05, 2025)
A hard-coded AES key vulnerability was reported in the Motorola GuideMe application, along with a lack of URI sanitation, could allow for a local attacker to read arbitrary files.
0
Attacker Value
Unknown

CVE-2024-3108

Disclosure Date: May 03, 2024 (last updated January 05, 2025)
An implicit intent vulnerability was reported for Motorola’s Time Weather Widget application that could allow a local application to acquire the location of the device without authorization. 
0
Attacker Value
Unknown

CVE-2023-41830

Disclosure Date: May 03, 2024 (last updated January 05, 2025)
An improper absolute path traversal vulnerability was reported for the Ready For application allowing a local application access to files without authorization. 
0
Attacker Value
Unknown

CVE-2023-41828

Disclosure Date: May 03, 2024 (last updated January 05, 2025)
An implicit intent export vulnerability was reported in the Motorola Phone application, that could allow unauthorized access to a non-exported content provider.  
0
Attacker Value
Unknown

CVE-2023-41826

Disclosure Date: May 03, 2024 (last updated January 05, 2025)
A PendingIntent hijacking vulnerability in Motorola Device Help (Genie) application that could allow local attackers to access files or interact with non-exported software components without permission. 
0