PT-2012-1562 · Cisco · Cisco Spa3102+4

Aleksandr Zaytsev

+1

·

Published

2012-06-13

·

Updated

2012-06-14

·

CVE-2011-2545

CVSS v2.0

4.3

Medium

VectorAV:N/AC:M/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions Cisco SPA8000 and SPA8800 versions prior to 6.1.11 Cisco SPA2102 and SPA3102 versions prior to 5.2.13 Cisco SPA 500 series IP phones versions prior to 7.4.9
Description A cross-site scripting (XSS) issue exists in the SIP implementation, allowing remote attackers to inject arbitrary web script or HTML via the FROM field of an INVITE message.
Recommendations For Cisco SPA8000 and SPA8800 versions prior to 6.1.11, update to version 6.1.11 or later. For Cisco SPA2102 and SPA3102 versions prior to 5.2.13, update to version 5.2.13 or later. For Cisco SPA 500 series IP phones versions prior to 7.4.9, update to version 7.4.9 or later.

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2011-2545

Affected Products

Cisco Spa 500 Series Ip Phones
Cisco Spa2102
Cisco Spa3102
Cisco Spa8000
Cisco Spa8800