First published: Thu Aug 03 2023(Updated: )
A vulnerability in the web-based management interface of Cisco Small Business SPA500 Series IP Phones could allow an unauthenticated, remote attacker to conduct XSS attacks. This vulnerability is due to insufficient validation of user-supplied input by the web-based management interface of the affected software. An attacker could exploit this vulnerability by persuading a user to click a crafted link. A successful exploit could allow the attacker to execute arbitrary script code in the context of the affected interface or access sensitive, browser-based information.
Credit: ykramarz@cisco.com ykramarz@cisco.com
Affected Software | Affected Version | How to fix |
---|---|---|
Cisco Spa500ds Firmware | ||
Cisco Spa500ds | ||
Cisco Spa500s Firmware | ||
Cisco Spa500s | ||
Cisco Spa501g Firmware | ||
Cisco Spa501g | ||
Cisco Spa502g Firmware | ||
Cisco Spa502g | ||
Cisco Spa504g Firmware | ||
Cisco Spa504g | ||
Cisco Spa508g Firmware | ||
Cisco Spa508g | ||
Cisco Spa509g Firmware | ||
Cisco Spa509g | ||
Cisco Spa512g Firmware | ||
Cisco Spa512g | ||
Cisco Spa514g Firmware | ||
Cisco Spa514g | ||
Cisco Spa525 Firmware | ||
Cisco Spa525 | ||
Cisco Spa525g Firmware | ||
Cisco Spa525g | ||
Cisco Spa525g2 Firmware | ||
Cisco Spa525g2 | ||
All of | ||
Cisco Spa500ds Firmware | ||
Cisco Spa500ds | ||
All of | ||
Cisco Spa500s Firmware | ||
Cisco Spa500s | ||
All of | ||
Cisco Spa501g Firmware | ||
Cisco Spa501g | ||
All of | ||
Cisco Spa502g Firmware | ||
Cisco Spa502g | ||
All of | ||
Cisco Spa504g Firmware | ||
Cisco Spa504g | ||
All of | ||
Cisco Spa508g Firmware | ||
Cisco Spa508g | ||
All of | ||
Cisco Spa509g Firmware | ||
Cisco Spa509g | ||
All of | ||
Cisco Spa512g Firmware | ||
Cisco Spa512g | ||
All of | ||
Cisco Spa514g Firmware | ||
Cisco Spa514g | ||
All of | ||
Cisco Spa525 Firmware | ||
Cisco Spa525 | ||
All of | ||
Cisco Spa525g Firmware | ||
Cisco Spa525g | ||
All of | ||
Cisco Spa525g2 Firmware | ||
Cisco Spa525g2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-20181 is a vulnerability in the web-based management interface of Cisco Small Business SPA500 Series IP Phones.
CVE-2023-20181 has a severity value of 6.1, which is categorized as medium.
CVE-2023-20181 allows an unauthenticated, remote attacker to conduct XSS attacks on Cisco Small Business SPA500 Series IP Phones.
The CWE ID for CVE-2023-20181 is 79.
To fix CVE-2023-20181, Cisco has released a security advisory that provides steps to mitigate the vulnerability. Please refer to the Cisco Security Advisory for more information.