cisco-sa-ata19x-multi-RDTEqRsy: Cisco ATA 190 Series Analog Telephone Adapter Firmware Vulnerabilities
Multiple vulnerabilities in Cisco ATA 190 Series Analog Telephone Adapter firmware, both on-premises and multiplatform, could allow a remote attacker to delete or change the configuration, execute commands as the root user, conduct a cross-site scripting (XSS) attack against a user of the interface, view passwords, conduct a cross-site request forgery (CSRF) attack, or reboot the device.For more information about these vulnerabilities, see the Details section of this advisory. Cisco has released firmware updates that address these vulnerabilities. There are no workarounds that address these vulnerabilities. However, there is a mitigation that addresses some of these vulnerabilities for Cisco ATA 191 on-premises firmware only.This advisory is available at the following link:https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ata19x-multi-RDTEqRsy
Affected Software
Event History
Frequently Asked Questions
What is the severity of cisco-sa-ata19x-multi-RDTEqRsy?
The cisco-sa-ata19x-multi-RDTEqRsy vulnerability is classified as critical, allowing significant unauthorized access and control.
How do I fix cisco-sa-ata19x-multi-RDTEqRsy?
To fix cisco-sa-ata19x-multi-RDTEqRsy, update the firmware of the Cisco ATA 190 Series Analog Telephone Adapter to the latest version provided by Cisco.
What types of attacks can be executed due to cisco-sa-ata19x-multi-RDTEqRsy?
The cisco-sa-ata19x-multi-RDTEqRsy vulnerability can facilitate remote command execution, configuration manipulation, and cross-site scripting (XSS) attacks.
Which products are affected by cisco-sa-ata19x-multi-RDTEqRsy?
The affected product is the Cisco ATA 190 Series Analog Telephone Adapter.
Is there a workaround for cisco-sa-ata19x-multi-RDTEqRsy?
Currently, there are no recommended workarounds for the cisco-sa-ata19x-multi-RDTEqRsy vulnerability; updating the firmware is the primary mitigation.