CVE-2024-20357: Cisco IP Phone 6821 With Multiplatform Firmware

Medium severity, CVSS 5.9. EPSS: 0.5% chance of exploitation in the next 30 days.

A vulnerability in the XML service of Cisco IP Phone firmware could allow an unauthenticated, remote attacker to initiate phone calls on an affected device. This vulnerability exists because bounds-checking does not occur while parsing XML requests. An attacker could exploit this vulnerability by sending a crafted XML request to an affected device. A successful exploit could allow the attacker to initiate calls or play sounds on the device.

Affected products

  • Cisco IP Phone 6821 With Multiplatform Firmware: up to and including 12.0.4
  • Cisco IP Phone 6841 With Multiplatform Firmware: up to and including 12.0.4
  • Cisco IP Phone 6851 With Multiplatform Firmware: up to and including 12.0.4
  • Cisco IP Phone 6861 With Multiplatform Firmware: up to and including 12.0.4
  • Cisco IP Phone 6871 With Multiplatform Firmware: up to and including 12.0.4
  • Cisco IP Phone 7811 With Multiplatform Firmware: up to and including 12.0.4
  • Cisco IP Phone 7821 With Multiplatform Firmware: up to and including 12.0.4
  • Cisco IP Phone 7832 With Multiplatform Firmware: up to and including 12.0.4
  • Cisco IP Phone 7841 With Multiplatform Firmware: up to and including 12.0.4
  • Cisco IP Phone 7861 With Multiplatform Firmware: up to and including 12.0.4
  • Cisco IP Phone 8811 With Multiplatform Firmware: up to and including 12.0.4
  • Cisco IP Phone 8832 With Multiplatform Firmware: up to and including 12.0.4
  • Cisco IP Phone 8841 With Multiplatform Firmware: up to and including 12.0.4
  • Cisco IP Phone 8845 With Multiplatform Firmware: up to and including 12.0.4
  • Cisco IP Phone 8851 With Multiplatform Firmware: up to and including 12.0.4
  • Cisco IP Phone 8861 With Multiplatform Firmware: up to and including 12.0.4
  • Cisco IP Phone 8865 With Multiplatform Firmware: up to and including 12.0.4
  • Cisco Video Phone 8875 Firmware: before 2.3.1.0101 (fixed in 2.3.1.0101)

Published 2024-05-01. Last modified 2026-06-17.