Cisco Small Business Ip Phones vulnerabilities

7 known vulnerabilities affecting cisco/cisco_small_business_ip_phones.

Total CVEs
7
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL3HIGH1MEDIUM3

Vulnerabilities

Page 1 of 1
CVE-2021-1379MEDIUMCVSS 6.5v7.4.8v7.4.3+30 more2024-11-18
CVE-2021-1379 [MEDIUM] CWE-120 CVE-2021-1379: Multiple vulnerabilities in the Cisco Discovery Protocol and Link Layer Discovery Protocol (LLD Multiple vulnerabilities in the Cisco Discovery Protocol and Link Layer Discovery Protocol (LLDP) implementations for Cisco IP Phone Series 68xx/78xx/88xx could allow an unauthenticated, adjacent attacker to execute code remotely or cause a reload of an affected IP phone. These vulnerabilities are due to missing checks when the IP phone processes a Ci
cvelistv5nvd
CVE-2024-20450CRITICALCVSS 9.8v7.6.0v7.6.2+31 more2024-08-07
CVE-2024-20450 [CRITICAL] CWE-120 CVE-2024-20450: Multiple vulnerabilities in the web-based management interface of Cisco Small Business SPA300 Series Multiple vulnerabilities in the web-based management interface of Cisco Small Business SPA300 Series IP Phones and Cisco Small Business SPA500 Series IP Phones could allow an unauthenticated, remote attacker to execute arbitrary commands on the underlying operating system with root privileges. These vulnerabilities exist because incoming HTTP pac
cvelistv5nvd
CVE-2024-20454CRITICALCVSS 9.8v7.6.0v7.6.2+31 more2024-08-07
CVE-2024-20454 [CRITICAL] CWE-120 CVE-2024-20454: Multiple vulnerabilities in the web-based management interface of Cisco Small Business SPA300 Series Multiple vulnerabilities in the web-based management interface of Cisco Small Business SPA300 Series IP Phones and Cisco Small Business SPA500 Series IP Phones could allow an unauthenticated, remote attacker to execute arbitrary commands on the underlying operating system with root privileges. These vulnerabilities exist because incoming HTTP pac
cvelistv5nvd
CVE-2024-20451HIGHCVSS 7.5v7.6.0v7.6.2+31 more2024-08-07
CVE-2024-20451 [HIGH] CWE-120 CVE-2024-20451: Multiple vulnerabilities in the web-based management interface of Cisco Small Business SPA300 Series Multiple vulnerabilities in the web-based management interface of Cisco Small Business SPA300 Series IP Phones and Cisco Small Business SPA500 Series IP Phones could allow an unauthenticated, remote attacker to cause an affected device to reload unexpectedly. These vulnerabilities exist because HTTP packets are not properly checked for errors. An att
cvelistv5nvd
CVE-2023-20218MEDIUMCVSS 6.1v7.6.0v7.6.2+30 more2023-08-03
CVE-2023-20218 [MEDIUM] CWE-80 CVE-2023-20218: A vulnerability in web-based management interface of Cisco SPA500 Series Analog Telephone Adapters ( A vulnerability in web-based management interface of Cisco SPA500 Series Analog Telephone Adapters (ATAs) could allow an authenticated, remote attacker to to modify a web page in the context of a user's browser. This vulnerability is due to insufficient validation of user-supplied input by the web-based management interface of the affected software.
cvelistv5nvd
CVE-2023-20181MEDIUMCVSS 6.1v7.6.0v7.6.2+30 more2023-08-03
CVE-2023-20181 [MEDIUM] CWE-80 CVE-2023-20181: A vulnerability in the web-based management interface of Cisco Small Business SPA500 Series IP Phone A vulnerability in the web-based management interface of Cisco Small Business SPA500 Series IP Phones could allow an unauthenticated, remote attacker to conduct XSS attacks. This vulnerability is due to insufficient validation of user-supplied input by the web-based management interface of the affected software. An attacker could exploit this vulnera
cvelistv5nvd
CVE-2023-20126CRITICALCVSS 9.8vn/a2023-05-04
CVE-2023-20126 [CRITICAL] CWE-306 CVE-2023-20126: A vulnerability in the web-based management interface of Cisco SPA112 2-Port Phone Adapters could al A vulnerability in the web-based management interface of Cisco SPA112 2-Port Phone Adapters could allow an unauthenticated, remote attacker to execute arbitrary code on an affected device. This vulnerability is due to a missing authentication process within the firmware upgrade function. An attacker could exploit this vulnerability by upgrading an
cvelistv5nvd