6.6

CVE-2019-15959

Cisco Small Business SPA500 Series IP Phones Local Script Execution Vulnerability

A vulnerability in Cisco Small Business SPA500 Series IP Phones could allow a physically proximate attacker to execute arbitrary commands on the device. The vulnerability is due to the presence of development testing and verification scripts that remained on the device. An attacker could exploit this vulnerability by accessing the physical interface of a device and inserting a USB storage device. A successful exploit could allow the attacker to execute scripts on the device in an elevated security context.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Cisco ≫ Spa500 Series Ip Phones Firmware Version <= 7.5.7\(5\)
   Cisco ≫ Spa500ds Version -
   Cisco ≫ Spa500s Version -
   Cisco ≫ Spa501g Version -
   Cisco ≫ Spa502g Version -
   Cisco ≫ Spa504g Version -
   Cisco ≫ Spa512g Version -
   Cisco ≫ Spa514g Version -
   Cisco ≫ Spa525g Version -
   Cisco ≫ Spa525g2 Version -
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.36% 0.28
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 6.6 0.7 5.9
CVSS:3.1/AV:P/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
NIST 4.6 3.9 6.4
AV:L/AC:L/Au:N/C:P/I:P/A:P
Cisco PSIRT 6.6 0.7 5.9
CVSS:3.0/AV:P/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CWE-20 Improper Input Validation

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20191106-spa500-script
Vendor Advisory