7.2

CVE-2015-6403

The TFTP implementation on Cisco Small Business SPA30x, SPA50x, SPA51x phones 7.5.7 improperly validates firmware-image file integrity, which allows local users to load a Trojan horse image by leveraging shell access, aka Bug ID CSCut67400.

Data is provided by the National Vulnerability Database (NVD)
CiscoSpa500 Firmware Version7.5.7
   CiscoSpa 500ds Version-
   CiscoSpa 500s Version-
   CiscoSpa 501g Version-
   CiscoSpa 502g Version-
   CiscoSpa 504g Version-
   CiscoSpa 508g Version-
   CiscoSpa 509g Version-
   CiscoSpa 512g Version-
   CiscoSpa 514g Version-
   CiscoSpa 525g2 Version-
CiscoSpa300 Firmware Version7.5.7
   CiscoSpa 301 Version-
   CiscoSpa 303 Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.09% 0.267
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 7.2 3.9 10
AV:L/AC:L/Au:N/C:C/I:C/A:C
CWE-20 Improper Input Validation

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.