First published: Wed Oct 16 2019(Updated: )
A vulnerability in the web-based management interface of Cisco SPA100 Series Analog Telephone Adapters (ATAs) could allow an authenticated, remote attacker to cause a denial of service condition on an affected device. The vulnerability is due to improper validation of user-supplied requests to the web-based management interface. An attacker could exploit this vulnerability by sending a crafted request to the web-based management interface of an affected device. A successful exploit could allow the attacker to cause the device to stop responding, requiring manual intervention for recovery.
Credit: ykramarz@cisco.com
Affected Software | Affected Version | How to fix |
---|---|---|
Cisco Spa112 Firmware | <1.4.1 | |
Cisco Spa112 Firmware | =1.4.1 | |
Cisco Spa112 Firmware | =1.4.1-sr1 | |
Cisco Spa112 Firmware | =1.4.1-sr2 | |
Cisco Spa112 Firmware | =1.4.1-sr3 | |
Cisco SPA112 | ||
Cisco Spa122 Firmware | <1.4.1 | |
Cisco Spa122 Firmware | =1.4.1 | |
Cisco Spa122 Firmware | =1.4.1-sr1 | |
Cisco Spa122 Firmware | =1.4.1-sr2 | |
Cisco Spa122 Firmware | =1.4.1-sr3 | |
Cisco SPA122 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-15258 is a vulnerability in the web-based management interface of Cisco SPA100 Series Analog Telephone Adapters (ATAs).
CVE-2019-15258 affects Cisco SPA112 Firmware version 1.4.1 and earlier.
CVE-2019-15258 affects Cisco SPA122 Firmware version 1.4.1 and earlier.
CVE-2019-15258 has a severity score of 6.5 (Medium).
To fix CVE-2019-15258, update to Cisco SPA112 Firmware version 1.4.1-sr4, or update to Cisco SPA122 Firmware version 1.4.1-sr4.