Cisco Analog Telephone Adaptor Software vulnerabilities
17 known vulnerabilities affecting cisco/cisco_analog_telephone_adaptor_software.
Total CVEs
17
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH8MEDIUM9
Vulnerabilities
Page 1 of 1
CVE-2024-20420P3HIGHCVSS 8.8v12.0.1 SR2v11.1.0+13 more2024-10-16
CVE-2024-20420 [HIGH] CWE-250 CVE-2024-20420: A vulnerability in the web-based management interface of Cisco ATA 190 Series Analog Telephone Adapt
A vulnerability in the web-based management interface of Cisco ATA 190 Series Analog Telephone Adapter firmware could allow an authenticated, remote attacker with low privileges to run commands as an Admin user.
This vulnerability is due to incorrect authorization verification by the HTTP server. An attacker could exploit this vulnerability by sendin
nvd
CVE-2021-34710P3HIGHCVSS 8.8vn/a2021-10-06
CVE-2021-34710 [HIGH] CWE-770 CVE-2021-34710: Multiple vulnerabilities in the Cisco ATA 190 Series Analog Telephone Adapter Software could allow a
Multiple vulnerabilities in the Cisco ATA 190 Series Analog Telephone Adapter Software could allow an attacker to perform a command injection attack resulting in remote code execution or cause a denial of service (DoS) condition on an affected device. For more information about these vulnerabilities, see the Details section of this advisory.
nvd
CVE-2024-20458P3HIGHCVSS 8.2v12.0.1 SR2v11.1.0+14 more2024-10-16
CVE-2024-20458 [HIGH] CWE-78 CVE-2024-20458: A vulnerability in the web-based management interface of Cisco ATA 190 Series Analog Telephone Adapt
A vulnerability in the web-based management interface of Cisco ATA 190 Series Analog Telephone Adapter firmware could allow an unauthenticated, remote attacker to view or delete the configuration or change the firmware on an affected device.
This vulnerability is due to a lack of authentication on specific HTTP endpoints. An attacker could exploit thi
nvd
CVE-2022-20690P3HIGHCVSS 8.8v1.2.1v1.2.2 SR1+16 more2022-12-12
CVE-2022-20690 [HIGH] CWE-130 CVE-2022-20690: Multiple vulnerabilities in the Cisco Discovery Protocol functionality of Cisco ATA 190 Series Analo
Multiple vulnerabilities in the Cisco Discovery Protocol functionality of Cisco ATA 190 Series Analog Telephone Adapter firmware could allow an unauthenticated, adjacent attacker to cause Cisco Discovery Protocol memory corruption on an affected device.
These vulnerabilities are due to missing length validation checks when processing Cisco Discovery P
nvd
CVE-2022-20689P3HIGHCVSS 8.8v1.2.1v1.2.2 SR1+16 more2022-12-12
CVE-2022-20689 [HIGH] CWE-130 CVE-2022-20689: Multiple vulnerabilities in the Cisco Discovery Protocol functionality of Cisco ATA 190 Series Analo
Multiple vulnerabilities in the Cisco Discovery Protocol functionality of Cisco ATA 190 Series Analog Telephone Adapter firmware could allow an unauthenticated, adjacent attacker to cause Cisco Discovery Protocol memory corruption on an affected device.
These vulnerabilities are due to missing length validation checks when processing Cisco Discovery P
nvd
CVE-2024-20459P3HIGHCVSS 7.2v12.0.1 SR2v11.1.0+14 more2024-10-16
CVE-2024-20459 [HIGH] CWE-78 CVE-2024-20459: A vulnerability in the web-based management interface of Cisco ATA 190 Multiplatform Series Analog T
A vulnerability in the web-based management interface of Cisco ATA 190 Multiplatform Series Analog Telephone Adapter firmware could allow an authenticated, remote attacker with high privileges to execute arbitrary commands as the root user on the underlying operating system.
This vulnerability is due to a lack of input sanitization in the web-based ma
nvd
CVE-2021-34735P3HIGHCVSS 7.5vn/a2021-10-06
CVE-2021-34735 [HIGH] CWE-770 CVE-2021-34735: Multiple vulnerabilities in the Cisco ATA 190 Series Analog Telephone Adapter Software could allow a
Multiple vulnerabilities in the Cisco ATA 190 Series Analog Telephone Adapter Software could allow an attacker to perform a command injection attack resulting in remote code execution or cause a denial of service (DoS) condition on an affected device. For more information about these vulnerabilities, see the Details section of this advisory.
nvd
CVE-2024-20463P3HIGHCVSS 7.1v12.0.1 SR2v11.1.0+14 more2024-10-16
CVE-2024-20463 [HIGH] CWE-305 CVE-2024-20463: A vulnerability in the web-based management interface of Cisco ATA 190 Series Analog Telephone Adapt
A vulnerability in the web-based management interface of Cisco ATA 190 Series Analog Telephone Adapter firmware could allow an unauthenticated, remote attacker to modify the configuration or reboot an affected device.
This vulnerability is due to the HTTP server allowing state changes in GET requests. An attacker could exploit this vulnerability by s
nvd
CVE-2024-20421P3MEDIUMCVSS 6.5v12.0.1 SR2v11.1.0+14 more2024-10-16
CVE-2024-20421 [MEDIUM] CWE-352 CVE-2024-20421: A vulnerability in the web-based management interface of Cisco ATA 190 Series Analog Telephone Adapt
A vulnerability in the web-based management interface of Cisco ATA 190 Series Analog Telephone Adapter firmware could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack and perform arbitrary actions on an affected device.
This vulnerability is due to insufficient CSRF protections for the web-based manage
nvd
CVE-2024-20461P4MEDIUMCVSS 6.0v12.0.1 SR2v11.1.0+14 more2024-10-16
CVE-2024-20461 [MEDIUM] CWE-78 CVE-2024-20461: A vulnerability in the CLI of Cisco ATA 190 Series Analog Telephone Adapter firmware could allo
A vulnerability in the CLI of Cisco ATA 190 Series Analog Telephone Adapter firmware could allow an authenticated, local attacker with high privileges to execute arbitrary commands as the root user.
This vulnerability exists because CLI input is not properly sanitized. An attacker could exploit this vulnerability by sending malicious characters to t
nvd
CVE-2022-20688P4MEDIUMCVSS 5.3v1.2.1v1.2.2 SR1+16 more2022-12-12
CVE-2022-20688 [MEDIUM] CWE-125 CVE-2022-20688: A vulnerability in the Cisco Discovery Protocol functionality of Cisco ATA 190 Series Analog Telepho
A vulnerability in the Cisco Discovery Protocol functionality of Cisco ATA 190 Series Analog Telephone Adapter firmware could allow an unauthenticated, remote attacker to execute arbitrary code on an affected device and cause Cisco Discovery Protocol service to restart.
This vulnerability is due to missing length validation of certain Cisco Discover
nvd
CVE-2022-20687P4MEDIUMCVSS 5.3v1.2.1v1.2.2 SR1+16 more2022-12-12
CVE-2022-20687 [MEDIUM] CWE-120 CVE-2022-20687: Multiple vulnerabilities in the Link Layer Discovery Protocol (LLDP) functionality of Cisco ATA 190
Multiple vulnerabilities in the Link Layer Discovery Protocol (LLDP) functionality of Cisco ATA 190 Series Analog Telephone Adapter firmware could allow an unauthenticated, remote attacker to execute arbitrary code on an affected device and cause the LLDP service to restart.
These vulnerabilities are due to missing length validation of certain LLDP p
nvd
CVE-2022-20686P4MEDIUMCVSS 5.3v1.2.1v1.2.2 SR1+16 more2022-12-12
CVE-2022-20686 [MEDIUM] CWE-130 CVE-2022-20686: Multiple vulnerabilities in the Link Layer Discovery Protocol (LLDP) functionality of Cisco ATA 190
Multiple vulnerabilities in the Link Layer Discovery Protocol (LLDP) functionality of Cisco ATA 190 Series Analog Telephone Adapter firmware could allow an unauthenticated, remote attacker to execute arbitrary code on an affected device and cause the LLDP service to restart.
These vulnerabilities are due to missing length validation of certain LLDP p
nvd
CVE-2022-20766P4MEDIUMCVSS 5.3v2.16(1)v2.16(2)+36 more2024-11-15
CVE-2022-20766 [MEDIUM] CWE-125 CVE-2022-20766: A vulnerability in the Cisco Discovery Protocol functionality of Cisco ATA 190 Series Adap
A vulnerability in the Cisco Discovery Protocol functionality of Cisco ATA 190 Series Adaptive Telephone Adapter firmware could allow an unauthenticated, remote attacker to cause a DoS condition on an affected device.
This vulnerability is due to an out-of-bounds read when processing Cisco Discovery Protocol packets. An attacker could exploit this v
nvd
CVE-2022-20691P4MEDIUMCVSS 6.5v1.2.1v1.2.2 SR1+36 more2022-12-12
CVE-2022-20691 [MEDIUM] CWE-400 CVE-2022-20691: A vulnerability in the Cisco Discovery Protocol functionality of Cisco ATA 190 Series Adaptive Telep
A vulnerability in the Cisco Discovery Protocol functionality of Cisco ATA 190 Series Adaptive Telephone Adapter firmware could allow an unauthenticated, adjacent attacker to cause a DoS condition of an affected device.
This vulnerability is due to missing length validation of certain Cisco Discovery Protocol packet header fields. An attacker could
nvd
CVE-2024-20460P4MEDIUMCVSS 6.1v12.0.1 SR2v11.1.0+14 more2024-10-16
CVE-2024-20460 [MEDIUM] CWE-80 CVE-2024-20460: A vulnerability in the web-based management interface of Cisco ATA 190 Series Analog Telephone Adapt
A vulnerability in the web-based management interface of Cisco ATA 190 Series Analog Telephone Adapter firmware could allow an unauthenticated, remote attacker to conduct a reflected cross-site scripting (XSS) attack against a user.
This vulnerability is due to insufficient validation of user input. An attacker could exploit this vulnerability by pe
nvd
CVE-2024-20462P4MEDIUMCVSS 5.5v11.1.0v11.1.0 MSR1+8 more2024-10-16
CVE-2024-20462 [MEDIUM] CWE-257 CVE-2024-20462: A vulnerability in the web-based management interface of Cisco ATA 190 Series Multiplatform Analog T
A vulnerability in the web-based management interface of Cisco ATA 190 Series Multiplatform Analog Telephone Adapter firmware could allow an authenticated, local attacker with low privileges to view passwords on an affected device.
This vulnerability is due to incorrect sanitization of HTML content from an affected device. A successful exploit coul
nvd