CVE-2019-15251
published 2019-10-16CVE-2019-15251: Multiple vulnerabilities in Cisco SPA100 Series Analog Telephone Adapters (ATAs) could allow an authenticated, adjacent attacker to execute arbitrary code with…
PriorityP345high8CVSS 3.1
AVAACLPRLUINSUCHIHAH
EPSS
0.58%
43.6th percentile
Multiple vulnerabilities in Cisco SPA100 Series Analog Telephone Adapters (ATAs) could allow an authenticated, adjacent attacker to execute arbitrary code with elevated privileges. The vulnerabilities are due to improper validation of user-supplied input to the web-based management interface. An attacker could exploit these vulnerabilities by authenticating to the web-based management interface and sending crafted requests to an affected device. A successful exploit could allow the attacker to execute arbitrary code with elevated privileges. Note: The web-based management interface is enabled by default.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | analog_telephone_adapters | — | — |
| cisco | cisco_spa112_2-port_phone_adapter | >= unspecified < n/a | n/a |
| cisco | spa112_firmware | < 1.4.1 | 1.4.1 |
| cisco | spa112_firmware | — | — |
| cisco | spa122_firmware | < 1.4.1 | 1.4.1 |
| cisco | spa122_firmware | — | — |
CVSS provenance
nvdv3.18.0HIGHCVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv3.08.0HIGHCVSS:3.0/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.05.2MEDIUMAV:A/AC:L/Au:S/C:P/I:P/A:P
vendor_cisco8.0HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Cisco
Multiple Cisco Analog Telephone Adapters Remote Code Execution Vulnerabilities
vendor_cisco·2019-10-16·CVSS 8.0
CVE-2019-15240 [HIGH] CWE-119 Multiple Cisco Analog Telephone Adapters Remote Code Execution Vulnerabilities
Multiple Cisco Analog Telephone Adapters Remote Code Execution Vulnerabilities
Multiple vulnerabilities in Cisco SPA Analog Telephone Adapters (ATAs) could allow an authenticated, adjacent attacker to execute arbitrary code with elevated privileges.
The vulnerabilities are due to improper validation of user-supplied input to the web-based management interface. An attacker could exploit these vulnerabilities by authenticating to the web-based management interface and sending crafted requests to an affected device. A successful exploit could allow the attacker to execute arbitrary code with elevated privileges.
Note: The web-based management interface is enabled by default.
There are no workarounds that address this vulnerability.
This advisory is available at the following link:
https://se
Cisco
Multiple Cisco Analog Telephone Adapters Remote Code Execution Vulnerabilities
vendor_cisco·CVSS 3.0
CVE-2019-15251 Multiple Cisco Analog Telephone Adapters Remote Code Execution Vulnerabilities
CVE-2019-15251: Multiple Cisco Analog Telephone Adapters Remote Code Execution Vulnerabilities
Multiple vulnerabilities in Cisco SPA Analog Telephone Adapters (ATAs) could allow an authenticated, adjacent attacker to execute arbitrary code with elevated privileges. The vulnerabilities are due to improper validation of user-supplied input to the web-based management interface. An attacker could exploit these vulnerabilities by authenticating to the web-based management interface and sending crafted requests to an affected device. A successful exploit could allow the attacker to execute arbitrary code with elevated privileges. Note: The web-based management interface is enabled by default. There are no
CVSS: 3.0
CWE: CWE-119, CWE-119
Bug IDs: CSCvq50494, CSCvr49341
GHSA
GHSA-vfj4-3qv2-wr7m: Multiple vulnerabilities in Cisco SPA100 Series Analog Telephone Adapters (ATAs) could allow an authenticated, adjacent attacker to execute arbitrary
ghsa_unreviewed·2022-05-24
CVE-2019-15251 [HIGH] CWE-119 GHSA-vfj4-3qv2-wr7m: Multiple vulnerabilities in Cisco SPA100 Series Analog Telephone Adapters (ATAs) could allow an authenticated, adjacent attacker to execute arbitrary
Multiple vulnerabilities in Cisco SPA100 Series Analog Telephone Adapters (ATAs) could allow an authenticated, adjacent attacker to execute arbitrary code with elevated privileges. The vulnerabilities are due to improper validation of user-supplied input to the web-based management interface. An attacker could exploit these vulnerabilities by authenticating to the web-based management interface and sending crafted requests to an affected device. A successful exploit could allow the attacker to execute arbitrary code with elevated privileges. Note: The web-based management interface is enabled by default.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2019-10-16
Published