← Back

CVE-2025-20158

nvd nist
Published: Feb 19, 2025Modified: Dec 15, 2025

JSON object

Loading...
4.4
Vector
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
Exploitability: 0.8 / Impact: 3.6
Source: psirt@cisco.com (Secondary)

Description

A vulnerability in the debug shell of Cisco Video Phone 8875 and Cisco Desk Phone 9800 Series could allow an authenticated, local attacker to access sensitive information on an affected device. To exploit this vulnerability, the attacker must have valid administrative credentials with SSH access on the affected device. SSH access is disabled by default. This vulnerability is due to insufficient validation of user-supplied input by the debug shell of an affected device. An attacker could exploit this vulnerability by sending a crafted SSH client command to the CLI. A successful exploit could allow the attacker to access sensitive information on the underlying operating system.

Affected (5)

5 products
Video Phone 8875 Firmware
Desk Phone 9871 Firmware
Desk Phone 9841 Firmware
Desk Phone 9851 Firmware
Desk Phone 9861 Firmware
Configuration A
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Before 3.3\(1\)
Running on/withPlatform Versions
Cisco
Video Phone 8875
All versions
Configuration B
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Before 3.3\(1\)
Running on/withPlatform Versions
Cisco
Desk Phone 9871
All versions
Configuration C
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Before 3.3\(1\)
Running on/withPlatform Versions
Cisco
Desk Phone 9841
All versions
Configuration D
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Before 3.3\(1\)
Running on/withPlatform Versions
Cisco
Desk Phone 9851
All versions
Configuration E
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Before 3.3\(1\)
Running on/withPlatform Versions
Cisco
Desk Phone 9861
All versions

Timeline

No history available yet.