PT-2024-7340 · Cisco · Cisco Ata 190 Series Analog Telephone Adapter

Published

2024-10-16

·

Updated

2024-10-22

·

CVE-2024-20461

CVSS v2.0

6.2

Medium

VectorAV:L/AC:L/Au:S/C:C/I:C/A:N
Name of the Vulnerable Software and Affected Versions: Cisco ATA 190 Series Analog Telephone Adapter firmware (affected versions not specified)
Description: The issue exists due to the lack of proper sanitization of CLI input, allowing an attacker to execute arbitrary commands as the root user by sending malicious characters to the CLI. This could enable the attacker to read and write to the underlying operating system as the root user.
Recommendations: At the moment, there is no information about a newer version that contains a fix for this vulnerability.

OS Command Injection

Weakness Enumeration

Related Identifiers

BDU:2024-08696
CVE-2024-20461

Affected Products

Cisco Ata 190 Series Analog Telephone Adapter