First published: Thu May 04 2023(Updated: )
A vulnerability in the web-based management interface of Cisco SPA112 2-Port Phone Adapters could allow an unauthenticated, remote attacker to execute arbitrary code on an affected device. This vulnerability is due to a missing authentication process within the firmware upgrade function. An attacker could exploit this vulnerability by upgrading an affected device to a crafted version of firmware. A successful exploit could allow the attacker to execute arbitrary code on the affected device with full privileges. Cisco has not released firmware updates to address this vulnerability.
Credit: ykramarz@cisco.com
Affected Software | Affected Version | How to fix |
---|---|---|
Cisco Spa112 Firmware | =1.4.1-sr9 | |
Cisco SPA112 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID of this Cisco SPA112 2-Port Phone Adapters vulnerability is CVE-2023-20126.
The severity rating of CVE-2023-20126 is critical (9.8).
This vulnerability allows an unauthenticated, remote attacker to execute arbitrary code on affected devices.
The Cisco SPA112 Firmware version 1.4.1-sr9 is affected by CVE-2023-20126.
No, the Cisco SPA112 device is not vulnerable to CVE-2023-20126.