PT-2019-1500 · Cisco · Cisco Small Business Spa5X5 Series Ip Phones+3
Jan Dubový
·
Publicado
2019-02-20
·
Atualizado
2023-03-23
·
CVE-2019-1683
CVSS v3.1
7.4
Alta
| Vetor | AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
Cisco Small Business SPA112 Series IP Phones version 1.4.2
Cisco Small Business SPA525 Series IP Phones version 7.6.2
Cisco Small Business SPA5X5 Series IP Phones version 7.6.2
Cisco Small Business SPA500 Series IP Phones version 1.4.2
Description
A vulnerability in the certificate handling component of the Cisco IP Phones could allow an unauthenticated, remote attacker to listen to or control some aspects of a Transport Level Security (TLS)-encrypted Session Initiation Protocol (SIP) conversation. The issue is due to the improper validation of server certificates. An attacker could exploit this by crafting a malicious server certificate to present to the client, potentially allowing them to eavesdrop on TLS-encrypted traffic and route or redirect calls initiated by an affected device.
Recommendations
For Cisco Small Business SPA112 Series IP Phones version 1.4.2, update the software to a version that properly validates server certificates.
For Cisco Small Business SPA525 Series IP Phones version 7.6.2, update the software to a version that properly validates server certificates.
For Cisco Small Business SPA5X5 Series IP Phones version 7.6.2, update the software to a version that properly validates server certificates.
For Cisco Small Business SPA500 Series IP Phones version 1.4.2, update the software to a version that properly validates server certificates.
Correção
Improper Certificate Validation
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Cisco Small Business Spa112 Series Ip Phones
Cisco Small Business Spa500 Series Ip Phones
Cisco Small Business Spa525 Series Ip Phones
Cisco Small Business Spa5X5 Series Ip Phones