Lucene search

K

Spa500 Firmware Security Vulnerabilities

cve
cve

CVE-2015-0670

The default configuration of Cisco Small Business IP phones SPA 300 7.5.5 and SPA 500 7.5.5 does not properly support authentication, which allows remote attackers to read audio-stream data or originate telephone calls via a crafted XML request, aka Bug ID CSCuo52482.

6.8AI Score

0.003EPSS

2015-03-21 01:59 AM
32
cve
cve

CVE-2015-6403

The TFTP implementation on Cisco Small Business SPA30x, SPA50x, SPA51x phones 7.5.7 improperly validates firmware-image file integrity, which allows local users to load a Trojan horse image by leveraging shell access, aka Bug ID CSCut67400.

6.4AI Score

0.0004EPSS

2015-12-15 05:59 AM
26
cve
cve

CVE-2016-1469

The HTTP framework on Cisco SPA300, SPA500, and SPA51x devices allows remote attackers to cause a denial of service (device outage) via a series of malformed HTTP requests, aka Bug ID CSCut67385.

7.5CVSS

7.4AI Score

0.003EPSS

2016-09-12 01:59 AM
66
cve
cve

CVE-2017-12271

A vulnerability in Cisco SPA300 and SPA500 Series IP Phones could allow an unauthenticated, remote attacker to execute unwanted actions on an affected device. The vulnerability is due to a lack of cross-site request forgery (CSRF) protection. An attacker could exploit this vulnerability by tricking...

8.8CVSS

8.8AI Score

0.002EPSS

2017-10-19 08:29 AM
24
1
cve
cve

CVE-2019-1683

A vulnerability in the certificate handling component of the Cisco SPA112, SPA525, and SPA5X5 Series IP Phones could allow an unauthenticated, remote attacker to listen to or control some aspects of a Transport Level Security (TLS)-encrypted Session Initiation Protocol (SIP) conversation. The vulne...

7.4CVSS

7.5AI Score

0.001EPSS

2019-02-25 05:29 PM
23