Vulnerability CVE-2014-3312


Published: 2014-07-09

Description:
The debug console interface on Cisco Small Business SPA300 and SPA500 phones does not properly perform authentication, which allows local users to execute arbitrary debug-shell commands, or read or modify data in memory or a filesystem, via direct access to this interface, aka Bug ID CSCun77435.

CVSS2 => (AV:L/AC:M/Au:N/C:C/I:C/A:C)

CVSS Base Score
Impact Subscore
Exploitability Subscore
6.9/10
10/10
3.4/10
Exploit range
Attack complexity
Authentication
Local
Medium
No required
Confidentiality impact
Integrity impact
Availability impact
Complete
Complete
Complete
Affected software
Cisco -> Spa 525g 5-line ip phone 
Cisco -> Spa901 1-line ip phone 
Cisco -> Spa922 1-line ip phone with 1-port ethernet 
Cisco -> Spa941 4-line ip phone with 1-port ethernet 
Cisco -> Spa942 4-line ip phone with 2-port switch 
Cisco -> Spa962 6-line ip phone with 2-port switch 
Cisco -> Spa 301 1 line ip phone 
Cisco -> Spa 303 3 line ip phone 
Cisco -> Spa 501g 8-line ip phone 
Cisco -> Spa 502g 1-line ip phone 
Cisco -> Spa 504g 4-line ip phone 
Cisco -> Spa 508g 8-line ip phone 
Cisco -> Spa 509g 12-line ip phone 
Cisco -> Spa 512g 1-line ip phone 
Cisco -> Spa 514g 4-line ip phone 
Cisco -> Spa 525g2 5-line ip phone 

 References:
http://xforce.iss.net/xforce/xfdb/94421
http://www.securitytracker.com/id/1030552
http://www.securityfocus.com/bid/68465
http://tools.cisco.com/security/center/content/CiscoSecurityNotice/CVE-2014-3312

Copyright 2024, cxsecurity.com

 

Back to Top