PT-2014-5207 · Cisco · Cisco Small Business Spa500+1
Publicado
2014-07-09
·
Atualizado
2017-08-29
·
CVE-2014-3312
CVSS v2.0
6.9
Média
| Vetor | AV:L/AC:M/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Cisco Small Business SPA300 and SPA500 phones (affected versions not specified)
Description
The issue concerns the debug console interface, which fails to properly authenticate users. This allows local users to execute arbitrary debug-shell commands, or read and modify data in memory or a filesystem by directly accessing the interface.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Improper Authentication
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Cisco Small Business Spa300
Cisco Small Business Spa500