PT-2012-1562 · Cisco · Cisco Spa3102+4

Aleksandr Zaytsev

+1

·

Publicado

2012-06-13

·

Atualizado

2012-06-14

·

CVE-2011-2545

CVSS v2.0

4.3

Média

VetorAV:N/AC:M/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions Cisco SPA8000 and SPA8800 versions prior to 6.1.11 Cisco SPA2102 and SPA3102 versions prior to 5.2.13 Cisco SPA 500 series IP phones versions prior to 7.4.9
Description A cross-site scripting (XSS) issue exists in the SIP implementation, allowing remote attackers to inject arbitrary web script or HTML via the FROM field of an INVITE message.
Recommendations For Cisco SPA8000 and SPA8800 versions prior to 6.1.11, update to version 6.1.11 or later. For Cisco SPA2102 and SPA3102 versions prior to 5.2.13, update to version 5.2.13 or later. For Cisco SPA 500 series IP phones versions prior to 7.4.9, update to version 7.4.9 or later.

Correção

XSS

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2011-2545

Produtos afetados

Cisco Spa 500 Series Ip Phones
Cisco Spa2102
Cisco Spa3102
Cisco Spa8000
Cisco Spa8800