PT-2019-1500 · Cisco · Cisco Small Business Spa5X5 Series Ip Phones+3

Jan Dubový

·

Publicado

2019-02-20

·

Atualizado

2023-03-23

·

CVE-2019-1683

CVSS v3.1

7.4

Alta

VetorAV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions Cisco Small Business SPA112 Series IP Phones version 1.4.2 Cisco Small Business SPA525 Series IP Phones version 7.6.2 Cisco Small Business SPA5X5 Series IP Phones version 7.6.2 Cisco Small Business SPA500 Series IP Phones version 1.4.2
Description A vulnerability in the certificate handling component of the Cisco IP Phones could allow an unauthenticated, remote attacker to listen to or control some aspects of a Transport Level Security (TLS)-encrypted Session Initiation Protocol (SIP) conversation. The issue is due to the improper validation of server certificates. An attacker could exploit this by crafting a malicious server certificate to present to the client, potentially allowing them to eavesdrop on TLS-encrypted traffic and route or redirect calls initiated by an affected device.
Recommendations For Cisco Small Business SPA112 Series IP Phones version 1.4.2, update the software to a version that properly validates server certificates. For Cisco Small Business SPA525 Series IP Phones version 7.6.2, update the software to a version that properly validates server certificates. For Cisco Small Business SPA5X5 Series IP Phones version 7.6.2, update the software to a version that properly validates server certificates. For Cisco Small Business SPA500 Series IP Phones version 1.4.2, update the software to a version that properly validates server certificates.

Correção

Improper Certificate Validation

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2019-00942
CVE-2019-1683

Produtos afetados

Cisco Small Business Spa112 Series Ip Phones
Cisco Small Business Spa500 Series Ip Phones
Cisco Small Business Spa525 Series Ip Phones
Cisco Small Business Spa5X5 Series Ip Phones