PT-2019-3146 · Cisco · Cisco Spa112

Published

2019-08-07

·

Updated

2023-03-29

·

CVE-2019-1956

CVSS v2.0

5.5

Medium

VectorAV:N/AC:L/Au:S/C:P/I:P/A:N
Name of the Vulnerable Software and Affected Versions Cisco SPA112 2-Port Phone Adapter (affected versions not specified)
Description The issue is related to insufficient validation of user-supplied input by the web-based interface of the affected device, allowing an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against another user of the device. An attacker could exploit this by inserting malicious code in one of the configuration fields, potentially executing arbitrary script code in the context of the affected interface or accessing sensitive, browser-based information.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

XSS

Weakness Enumeration

Related Identifiers

BDU:2019-03133
CVE-2019-1956

Affected Products

Cisco Spa112