← Vulnerability feed

Vulnerability record · CVE-2024-20534 · published 6 November 2024

CVE-2024-20534: Cisco desk phone 9841 with multiplatform firmware cross-site scripting vulnerability

Cisco · Desk Phone 9841 With Multiplatform Firmware

A vulnerability in the web UI of Cisco Desk Phone 9800 Series, Cisco IP Phone 6800, 7800, and 8800 Series, and Cisco Video Phone 8875 with Cisco Multiplatform Firmware could allow an authenticated, remote attacker to conduct stored cross-site scripting (XSS) attacks against users. This vulnerability exists because the web UI of an affected device does not properly validate user-supplied input. An attacker could exploit this vulnerability by injecting malicious code into specific pages of the interface. A successful exploit could allow the attacker to execute arbitrary script code in the context of the affected interface or access sensitive, browser-based information. Note: To exploit this vulnerability, Web Access must be enabled on the phone and the attacker must have Admin credentials on the device. Web Access is disabled by default.

4.8 CVSS 3.1 Medium EPSS 0.28% · top 81.9% CWE-79 · Cross-site scripting
4.8CVSS 3.1 base score
0.28%EPSS exploitation probability, 30 days
NoNot in CISA KEV
23Affected product versions listed by NVD
1References
17 Jun 2026Last modified by NVD

Description

A vulnerability in the web UI of Cisco Desk Phone 9800 Series, Cisco IP Phone 6800, 7800, and 8800 Series, and Cisco Video Phone 8875 with Cisco Multiplatform Firmware could allow an authenticated, remote attacker to conduct stored cross-site scripting (XSS) attacks against users. This vulnerability exists because the web UI of an affected device does not properly validate user-supplied input. An attacker could exploit this vulnerability by injecting malicious code into specific pages of the interface. A successful exploit could allow the attacker to execute arbitrary script code in the context of the affected interface or access sensitive, browser-based information. Note: To exploit this vulnerability, Web Access must be enabled on the phone and the attacker must have Admin credentials on the device. Web Access is disabled by default.

CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N

Affected products

23 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2024-20534 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

7.5CVE-2024-20376Cisco video phone 8875 firmware out-of-bounds write vulnerabilityA vulnerability in the web-based management interface of Cisco IP Phone firmware could allow an unauthenticated, remote attacker to cause an affected…EPSS 0.88%7.5CVE-2024-20378Cisco ip phone 6821 with multiplatform firmware vulnerabilityA vulnerability in the web-based management interface of Cisco IP Phone firmware could allow an unauthenticated, remote attacker to retrieve sensitiv…EPSS 0.81%6.5CVE-2021-1379Cisco ip conference phone 7832 firmware classic buffer overflow vulnerabilityMultiple vulnerabilities in the Cisco Discovery Protocol and Link Layer Discovery Protocol (LLDP) implementations for Cisco IP Phone Series…EPSS 0.33%6.5CVE-2023-20221Cisco video phone 8875 firmware cross-site request forgery vulnerabilityA vulnerability in the web-based management interface of Cisco IP Phone 6800, 7800, and 8800 Series with Multiplatform Firmware could allow an unauth…EPSS 0.33%5.9CVE-2024-20357Cisco ip phone 6871 with multiplatform firmware out-of-bounds write vulnerabilityA vulnerability in the XML service of Cisco IP Phone firmware could allow an unauthenticated, remote attacker to initiate phone calls on an affected …EPSS 0.50%4.8CVE-2024-20533Cisco desk phone 9841 with multiplatform firmware cross-site scripting vulnerabilityA vulnerability in the web UI of Cisco Desk Phone 9800 Series, Cisco IP Phone 6800, 7800, and 8800 Series, and Cisco Video Phone 8875 with Cisco Mult…EPSS 0.28%6.1CVE-2026-42897Microsoft Exchange Server XSS enables spoofingMicrosoft Exchange Server and Exchange Server Subscription Edition fail to neutralize input during web page generation, a cross-site scripting flaw (…KEVEPSS 0.52%analysed6.1CVE-2025-48700Zimbra Classic UI stored XSS via crafted email HTMLZimbra Collaboration Suite Classic UI fails to properly sanitize HTML content in email messages, allowing crafted tag structures and attribute values…KEVEPSS 1.7%analysed

Source: NIST National Vulnerability Database (record CVE-2024-20534), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.