PT-2012-1562 · Cisco · Cisco Spa3102+4
Aleksandr Zaytsev
+1
·
Published
2012-06-13
·
Updated
2012-06-14
·
CVE-2011-2545
CVSS v2.0
4.3
Medium
| Vector | AV:N/AC:M/Au:N/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
Cisco SPA8000 and SPA8800 versions prior to 6.1.11
Cisco SPA2102 and SPA3102 versions prior to 5.2.13
Cisco SPA 500 series IP phones versions prior to 7.4.9
Description
A cross-site scripting (XSS) issue exists in the SIP implementation, allowing remote attackers to inject arbitrary web script or HTML via the
FROM field of an INVITE message.Recommendations
For Cisco SPA8000 and SPA8800 versions prior to 6.1.11, update to version 6.1.11 or later.
For Cisco SPA2102 and SPA3102 versions prior to 5.2.13, update to version 5.2.13 or later.
For Cisco SPA 500 series IP phones versions prior to 7.4.9, update to version 7.4.9 or later.
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Cisco Spa 500 Series Ip Phones
Cisco Spa2102
Cisco Spa3102
Cisco Spa8000
Cisco Spa8800