First published: Wed Jul 09 2014(Updated: )
The debug console interface on Cisco Small Business SPA300 and SPA500 phones does not properly perform authentication, which allows local users to execute arbitrary debug-shell commands, or read or modify data in memory or a filesystem, via direct access to this interface, aka Bug ID CSCun77435.
Credit: ykramarz@cisco.com
Affected Software | Affected Version | How to fix |
---|---|---|
Cisco Spa 301 1 Line Ip Phone | ||
Cisco Spa 303 3 Line Ip Phone | ||
Cisco Spa 501g 8-line Ip Phone | ||
Cisco Spa 502g 1-line Ip Phone | ||
Cisco Spa 504g 4-line Ip Phone | ||
Cisco Spa 508g 8-line Ip Phone | ||
Cisco Spa 509g 12-line Ip Phone | ||
Cisco Spa 512g 1-line Ip Phone | ||
Cisco Spa 514g 4-line Ip Phone | ||
Cisco Spa 525g 5-line Ip Phone | ||
Cisco Spa 525g2 5-line Ip Phone | ||
Cisco Spa901 1-line Ip Phone | ||
Cisco Spa922 1-line Ip Phone With 1-port Ethernet | ||
Cisco Spa941 4-line Ip Phone With 1-port Ethernet | ||
Cisco Spa942 4-line Ip Phone With 2-port Switch | ||
Cisco Spa962 6-line Ip Phone With 2-port Switch |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.