6.1

CVE-2023-20181

A vulnerability in the web-based management interface of Cisco Small Business SPA500 Series IP Phones could allow an unauthenticated, remote attacker to conduct XSS attacks. This vulnerability is due to insufficient validation of user-supplied input by the web-based management interface of the affected software. An attacker could exploit this vulnerability by persuading a user to click a crafted link. A successful exploit could allow the attacker to execute arbitrary script code in the context of the affected interface or access sensitive, browser-based information.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Cisco ≫ Spa500ds Firmware Version -
   Cisco ≫ Spa500ds Version -
Cisco ≫ Spa500s Firmware Version -
   Cisco ≫ Spa500s Version -
Cisco ≫ Spa501g Firmware Version -
   Cisco ≫ Spa501g Version -
Cisco ≫ Spa502g Firmware Version -
   Cisco ≫ Spa502g Version -
Cisco ≫ Spa504g Firmware Version -
   Cisco ≫ Spa504g Version -
Cisco ≫ Spa508g Firmware Version -
   Cisco ≫ Spa508g Version -
Cisco ≫ Spa509g Firmware Version -
   Cisco ≫ Spa509g Version -
Cisco ≫ Spa512g Firmware Version -
   Cisco ≫ Spa512g Version -
Cisco ≫ Spa514g Firmware Version -
   Cisco ≫ Spa514g Version -
Cisco ≫ Spa525 Firmware Version -
   Cisco ≫ Spa525 Version -
Cisco ≫ Spa525g Firmware Version -
   Cisco ≫ Spa525g Version -
Cisco ≫ Spa525g2 Firmware Version -
   Cisco ≫ Spa525g2 Version -
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.53% 0.412
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 6.1 2.8 2.7
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Cisco PSIRT 6.1 2.8 2.7
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

CWE-80 Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS)

The product receives input from an upstream component, but it does not neutralize or incorrectly neutralizes special characters such as "<", ">", and "&" that could be interpreted as web-scripting elements when they are sent to a downstream component that processes web pages.

https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-spa-web-multi-7kvPmu2F
Vendor Advisory