Cisco Spa112 Firmware vulnerabilities

20 known vulnerabilities affecting cisco/spa112_firmware.

Total CVEs
20
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL1HIGH14MEDIUM5

Vulnerabilities

Page 1 of 1
CVE-2023-20126CRITICALCVSS 9.8v1.4.12023-05-04
CVE-2023-20126 [CRITICAL] CWE-306 CVE-2023-20126: A vulnerability in the web-based management interface of Cisco SPA112 2-Port Phone Adapters could al A vulnerability in the web-based management interface of Cisco SPA112 2-Port Phone Adapters could allow an unauthenticated, remote attacker to execute arbitrary code on an affected device. This vulnerability is due to a missing authentication process within the firmware upgrade function. An attacker could exploit this vulnerability by upgrading an
nvd
CVE-2019-15241HIGHCVSS 8.0fixed in 1.4.1v1.4.12019-10-16
CVE-2019-15241 [HIGH] CWE-119 CVE-2019-15241: Multiple vulnerabilities in Cisco SPA100 Series Analog Telephone Adapters (ATAs) could allow an auth Multiple vulnerabilities in Cisco SPA100 Series Analog Telephone Adapters (ATAs) could allow an authenticated, adjacent attacker to execute arbitrary code with elevated privileges. The vulnerabilities are due to improper validation of user-supplied input to the web-based management interface. An attacker could exploit these vulnerabilities by authenti
nvd
CVE-2019-15246HIGHCVSS 8.0fixed in 1.4.1v1.4.12019-10-16
CVE-2019-15246 [HIGH] CWE-119 CVE-2019-15246: Multiple vulnerabilities in Cisco SPA100 Series Analog Telephone Adapters (ATAs) could allow an auth Multiple vulnerabilities in Cisco SPA100 Series Analog Telephone Adapters (ATAs) could allow an authenticated, adjacent attacker to execute arbitrary code with elevated privileges. The vulnerabilities are due to improper validation of user-supplied input to the web-based management interface. An attacker could exploit these vulnerabilities by authenti
nvd
CVE-2019-15252HIGHCVSS 8.0fixed in 1.4.1v1.4.12019-10-16
CVE-2019-15252 [HIGH] CWE-119 CVE-2019-15252: Multiple vulnerabilities in Cisco SPA100 Series Analog Telephone Adapters (ATAs) could allow an auth Multiple vulnerabilities in Cisco SPA100 Series Analog Telephone Adapters (ATAs) could allow an authenticated, adjacent attacker to execute arbitrary code with elevated privileges. The vulnerabilities are due to improper validation of user-supplied input to the web-based management interface. An attacker could exploit these vulnerabilities by authenti
nvd
CVE-2019-15242HIGHCVSS 8.0fixed in 1.4.1v1.4.12019-10-16
CVE-2019-15242 [HIGH] CWE-119 CVE-2019-15242: Multiple vulnerabilities in Cisco SPA100 Series Analog Telephone Adapters (ATAs) could allow an auth Multiple vulnerabilities in Cisco SPA100 Series Analog Telephone Adapters (ATAs) could allow an authenticated, adjacent attacker to execute arbitrary code with elevated privileges. The vulnerabilities are due to improper validation of user-supplied input to the web-based management interface. An attacker could exploit these vulnerabilities by authenti
nvd
CVE-2019-15247HIGHCVSS 8.0fixed in 1.4.1v1.4.12019-10-16
CVE-2019-15247 [HIGH] CWE-119 CVE-2019-15247: Multiple vulnerabilities in Cisco SPA100 Series Analog Telephone Adapters (ATAs) could allow an auth Multiple vulnerabilities in Cisco SPA100 Series Analog Telephone Adapters (ATAs) could allow an authenticated, adjacent attacker to execute arbitrary code with elevated privileges. The vulnerabilities are due to improper validation of user-supplied input to the web-based management interface. An attacker could exploit these vulnerabilities by authenti
nvd
CVE-2019-15250HIGHCVSS 8.0fixed in 1.4.1v1.4.12019-10-16
CVE-2019-15250 [HIGH] CWE-119 CVE-2019-15250: Multiple vulnerabilities in Cisco SPA100 Series Analog Telephone Adapters (ATAs) could allow an auth Multiple vulnerabilities in Cisco SPA100 Series Analog Telephone Adapters (ATAs) could allow an authenticated, adjacent attacker to execute arbitrary code with elevated privileges. The vulnerabilities are due to improper validation of user-supplied input to the web-based management interface. An attacker could exploit these vulnerabilities by authenti
nvd
CVE-2019-15244HIGHCVSS 8.0fixed in 1.4.1v1.4.12019-10-16
CVE-2019-15244 [HIGH] CWE-119 CVE-2019-15244: Multiple vulnerabilities in Cisco SPA100 Series Analog Telephone Adapters (ATAs) could allow an auth Multiple vulnerabilities in Cisco SPA100 Series Analog Telephone Adapters (ATAs) could allow an authenticated, adjacent attacker to execute arbitrary code with elevated privileges. The vulnerabilities are due to improper validation of user-supplied input to the web-based management interface. An attacker could exploit these vulnerabilities by authenti
nvd
CVE-2019-15243HIGHCVSS 8.0fixed in 1.4.1v1.4.12019-10-16
CVE-2019-15243 [HIGH] CWE-119 CVE-2019-15243: Multiple vulnerabilities in Cisco SPA100 Series Analog Telephone Adapters (ATAs) could allow an auth Multiple vulnerabilities in Cisco SPA100 Series Analog Telephone Adapters (ATAs) could allow an authenticated, adjacent attacker to execute arbitrary code with elevated privileges. The vulnerabilities are due to improper validation of user-supplied input to the web-based management interface. An attacker could exploit these vulnerabilities by authenti
nvd
CVE-2019-15251HIGHCVSS 8.0fixed in 1.4.1v1.4.12019-10-16
CVE-2019-15251 [HIGH] CWE-119 CVE-2019-15251: Multiple vulnerabilities in Cisco SPA100 Series Analog Telephone Adapters (ATAs) could allow an auth Multiple vulnerabilities in Cisco SPA100 Series Analog Telephone Adapters (ATAs) could allow an authenticated, adjacent attacker to execute arbitrary code with elevated privileges. The vulnerabilities are due to improper validation of user-supplied input to the web-based management interface. An attacker could exploit these vulnerabilities by authenti
nvd
CVE-2019-15248HIGHCVSS 8.0fixed in 1.4.1v1.4.12019-10-16
CVE-2019-15248 [HIGH] CWE-119 CVE-2019-15248: Multiple vulnerabilities in Cisco SPA100 Series Analog Telephone Adapters (ATAs) could allow an auth Multiple vulnerabilities in Cisco SPA100 Series Analog Telephone Adapters (ATAs) could allow an authenticated, adjacent attacker to execute arbitrary code with elevated privileges. The vulnerabilities are due to improper validation of user-supplied input to the web-based management interface. An attacker could exploit these vulnerabilities by authenti
nvd
CVE-2019-15249HIGHCVSS 8.0fixed in 1.4.1v1.4.12019-10-16
CVE-2019-15249 [HIGH] CWE-119 CVE-2019-15249: Multiple vulnerabilities in Cisco SPA100 Series Analog Telephone Adapters (ATAs) could allow an auth Multiple vulnerabilities in Cisco SPA100 Series Analog Telephone Adapters (ATAs) could allow an authenticated, adjacent attacker to execute arbitrary code with elevated privileges. The vulnerabilities are due to improper validation of user-supplied input to the web-based management interface. An attacker could exploit these vulnerabilities by authenti
nvd
CVE-2019-15240HIGHCVSS 8.0fixed in 1.4.1v1.4.12019-10-16
CVE-2019-15240 [HIGH] CWE-119 CVE-2019-15240: Multiple vulnerabilities in Cisco SPA100 Series Analog Telephone Adapters (ATAs) could allow an auth Multiple vulnerabilities in Cisco SPA100 Series Analog Telephone Adapters (ATAs) could allow an authenticated, adjacent attacker to execute arbitrary code with elevated privileges. The vulnerabilities are due to improper validation of user-supplied input to the web-based management interface. An attacker could exploit these vulnerabilities by authenti
nvd
CVE-2019-15245HIGHCVSS 8.0fixed in 1.4.1v1.4.12019-10-16
CVE-2019-15245 [HIGH] CWE-119 CVE-2019-15245: Multiple vulnerabilities in Cisco SPA100 Series Analog Telephone Adapters (ATAs) could allow an auth Multiple vulnerabilities in Cisco SPA100 Series Analog Telephone Adapters (ATAs) could allow an authenticated, adjacent attacker to execute arbitrary code with elevated privileges. The vulnerabilities are due to improper validation of user-supplied input to the web-based management interface. An attacker could exploit these vulnerabilities by authenti
nvd
CVE-2019-12704MEDIUMCVSS 6.5fixed in 1.4.1v1.4.12019-10-16
CVE-2019-12704 [MEDIUM] CWE-200 CVE-2019-12704: A vulnerability in the web-based management interface of Cisco SPA100 Series Analog Telephone Adapte A vulnerability in the web-based management interface of Cisco SPA100 Series Analog Telephone Adapters (ATAs) could allow an authenticated, remote attacker to view the contents of arbitrary files on an affected device. The vulnerability is due to improper input validation in the web-based management interface. An attacker could exploit this vulnerab
nvd
CVE-2019-15258MEDIUMCVSS 6.5fixed in 1.4.1v1.4.12019-10-16
CVE-2019-15258 [MEDIUM] CWE-399 CVE-2019-15258: A vulnerability in the web-based management interface of Cisco SPA100 Series Analog Telephone Adapte A vulnerability in the web-based management interface of Cisco SPA100 Series Analog Telephone Adapters (ATAs) could allow an authenticated, remote attacker to cause a denial of service condition on an affected device. The vulnerability is due to improper validation of user-supplied requests to the web-based management interface. An attacker could ex
nvd
CVE-2019-12708MEDIUMCVSS 6.5fixed in 1.4.1v1.4.12019-10-16
CVE-2019-12708 [MEDIUM] CWE-200 CVE-2019-12708: A vulnerability in the web-based management interface of Cisco SPA100 Series Analog Telephone Adapte A vulnerability in the web-based management interface of Cisco SPA100 Series Analog Telephone Adapters (ATAs) could allow an authenticated, remote attacker to access sensitive information on an affected device. The vulnerability is due to unsafe handling of user credentials. An attacker could exploit this vulnerability by viewing portions of the web
nvd
CVE-2019-15257MEDIUMCVSS 6.5fixed in 1.4.1v1.4.12019-10-16
CVE-2019-15257 [MEDIUM] CWE-200 CVE-2019-15257: A vulnerability in the web-based management interface of Cisco SPA100 Series Analog Telephone Adapte A vulnerability in the web-based management interface of Cisco SPA100 Series Analog Telephone Adapters (ATAs) could allow an authenticated, remote attacker to access sensitive information on an affected device. The vulnerability is due to improper restrictions on configuration information. An attacker could exploit this vulnerability by sending a re
nvd
CVE-2019-12702MEDIUMCVSS 5.4fixed in 1.4.1v1.4.12019-10-16
CVE-2019-12702 [MEDIUM] CWE-79 CVE-2019-12702: A vulnerability in the web-based management interface of Cisco SPA100 Series Analog Telephone Adapte A vulnerability in the web-based management interface of Cisco SPA100 Series Analog Telephone Adapters (ATAs) could allow an authenticated, remote attacker to conduct cross-site scripting attacks. The vulnerability is due to insufficient validation of user-supplied input by the web-based management interface of the affected software. An attacker coul
nvd
CVE-2019-1683HIGHCVSS 7.4v1.4.22019-02-25
CVE-2019-1683 [HIGH] CWE-295 CVE-2019-1683: A vulnerability in the certificate handling component of the Cisco SPA112, SPA525, and SPA5X5 Series A vulnerability in the certificate handling component of the Cisco SPA112, SPA525, and SPA5X5 Series IP Phones could allow an unauthenticated, remote attacker to listen to or control some aspects of a Transport Level Security (TLS)-encrypted Session Initiation Protocol (SIP) conversation. The vulnerability is due to the improper validation of server cer
nvd