7.4
CVE-2019-1683
- EPSS 0.87%
- Veröffentlicht 25.02.2019 17:29:00
- Zuletzt bearbeitet 21.11.2024 04:37:05
- Erkennungen
Cisco SPA112, SPA525, and SPA5x5 Series IP Phones Certificate Validation Vulnerability
A vulnerability in the certificate handling component of the Cisco SPA112, SPA525, and SPA5X5 Series IP Phones could allow an unauthenticated, remote attacker to listen to or control some aspects of a Transport Level Security (TLS)-encrypted Session Initiation Protocol (SIP) conversation. The vulnerability is due to the improper validation of server certificates. An attacker could exploit this vulnerability by crafting a malicious server certificate to present to the client. An exploit could allow an attacker to eavesdrop on TLS-encrypted traffic and potentially route or redirect calls initiated by an affected device. Affected software include version 7.6.2 of the Cisco Small Business SPA525 Series IP Phones and Cisco Small Business SPA5X5 Series IP Phones and version 1.4.2 of the Cisco Small Business SPA500 Series IP Phones and Cisco Small Business SPA112 Series IP Phones.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Cisco ≫ Spa112 Firmware Version 1.4.2
Cisco ≫ Spa525 Firmware Version 7.6.2
Cisco ≫ Spa5x5 Firmware Version 7.6.2
Cisco ≫ Spa500 Firmware Version 1.4.2
Cisco ≫ Spa500s Firmware Version 1.4.2
Cisco ≫ Spa500ds Firmware Version 1.4.2
Cisco ≫ Spa501g Firmware Version 1.4.2
Cisco ≫ Spa502g Firmware Version 1.4.2
Cisco ≫ Spa504g Firmware Version 1.4.2
Cisco ≫ Spa508g Firmware Version 1.4.2
Cisco ≫ Spa509g Firmware Version 1.4.2
Cisco ≫ Spa512g Firmware Version 1.4.2
Cisco ≫ Spa514g Firmware Version 1.4.2
Cisco ≫ Spa525g Firmware Version 1.4.2
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.87% | 0.542 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 7.4 | 2.2 | 5.2 |
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
|
| NIST | 5.8 | 8.6 | 4.9 |
AV:N/AC:M/Au:N/C:P/I:P/A:N
|
| Cisco PSIRT | 6.5 | 2.2 | 4.2 |
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:L/A:N
|
CWE-295 Improper Certificate Validation
The product does not validate, or incorrectly validates, a certificate.
http://www.securityfocus.com/bid/107111
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20190220-ipphone-certs