PT-2012-1562 · Cisco · Cisco Spa3102+4
Aleksandr Zaytsev
+1
·
Publicado
2012-06-13
·
Atualizado
2012-06-14
·
CVE-2011-2545
CVSS v2.0
4.3
Média
| Vetor | AV:N/AC:M/Au:N/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
Cisco SPA8000 and SPA8800 versions prior to 6.1.11
Cisco SPA2102 and SPA3102 versions prior to 5.2.13
Cisco SPA 500 series IP phones versions prior to 7.4.9
Description
A cross-site scripting (XSS) issue exists in the SIP implementation, allowing remote attackers to inject arbitrary web script or HTML via the
FROM field of an INVITE message.Recommendations
For Cisco SPA8000 and SPA8800 versions prior to 6.1.11, update to version 6.1.11 or later.
For Cisco SPA2102 and SPA3102 versions prior to 5.2.13, update to version 5.2.13 or later.
For Cisco SPA 500 series IP phones versions prior to 7.4.9, update to version 7.4.9 or later.
Correção
XSS
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Cisco Spa 500 Series Ip Phones
Cisco Spa2102
Cisco Spa3102
Cisco Spa8000
Cisco Spa8800