First published: Wed Jul 09 2014(Updated: )
Cross-site scripting (XSS) vulnerability in the web user interface on Cisco Small Business SPA300 and SPA500 phones allows remote attackers to inject arbitrary web script or HTML via a crafted URL, aka Bug ID CSCuo52582.
Credit: ykramarz@cisco.com
Affected Software | Affected Version | How to fix |
---|---|---|
Cisco SPA 301 1-line IP Phone | ||
Cisco SPA300 Series IP Phone | ||
Cisco SPA 501G | ||
Cisco SPA 502G 1-Line IP Phone | ||
Cisco SPA 504G | ||
Cisco SPA500 series IP phone | ||
Cisco SPA 509g 12-line IP Phone | ||
Cisco SPA 512G 1-line IP Phone | ||
Cisco SPA514G | ||
Cisco SPA 525g 5-Line IP Phone | ||
Cisco SPA 525G2 5-Line IP Phone | ||
Cisco SPA 901 1-Line IP Phone | ||
Cisco SPA 922 1-Line IP Phone with 1-Port Ethernet | ||
Cisco SPA941 4-Line IP Phone | ||
Cisco SPA942 4-Line IP Phone | ||
Cisco SPA 962 IP Phone |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2014-3313 is classified as low.
To fix CVE-2014-3313, users should apply the latest firmware updates provided by Cisco.
CVE-2014-3313 affects various models of Cisco SPA300 and SPA500 series IP phones.
CVE-2014-3313 is categorized as a cross-site scripting (XSS) vulnerability.
Yes, CVE-2014-3313 can be exploited remotely by attackers through a crafted URL.