cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
764
Views
0
Helpful
3
Replies

Cisco IP Phone 7940 -Vulnerability issue

Jagsuvce G
Level 1
Level 1

Hi,

As per the vulnerability report (Qualys Guard), we are seeing couple of vulnerabilities wrt 7940 IP Phones.

The report says...

OS:

Linux 2.4-2.6 / Embedded Device / F5 Networks Big-IP

Issue:

Web Server/ Web Application Vulnerable to Cross-Site Scripting Attacks

Threat:

Your Web server/application does not filter script embedding from links displayed on a server's Web site.

Pls suggest what action needs to be take to resolve this issue.

1 Accepted Solution

Accepted Solutions

Because the phone is not really a web site and does not supports scripting at all.

You can also disable web access and that's it.

View solution in original post

3 Replies 3

paolo bevilacqua
Hall of Fame
Hall of Fame

False alarm, no action needed.

Hi,

Thanks for the update.

Any additional inputs how it could be a false alarm.

Regards

Jagadish G

Because the phone is not really a web site and does not supports scripting at all.

You can also disable web access and that's it.