The debug console interface on Cisco Small Business SPA300 and SPA500 phones does not properly perform authentication, which allows local users to execute arbitrary debug-shell commands, or read or modify data in memory or a filesystem, via direct access to this interface, aka Bug ID CSCun77435.
Project Subscriptions
| Vendors | Products |
|---|---|
|
Cisco
Subscribe
|
Spa901 1-line Ip Phone
Subscribe
Spa922 1-line Ip Phone With 1-port Ethernet
Subscribe
Spa941 4-line Ip Phone With 1-port Ethernet
Subscribe
Spa942 4-line Ip Phone With 2-port Switch
Subscribe
Spa962 6-line Ip Phone With 2-port Switch
Subscribe
Spa 301 1 Line Ip Phone
Subscribe
Spa 303 3 Line Ip Phone
Subscribe
Spa 501g 8-line Ip Phone
Subscribe
Spa 502g 1-line Ip Phone
Subscribe
Spa 504g 4-line Ip Phone
Subscribe
Spa 508g 8-line Ip Phone
Subscribe
Spa 509g 12-line Ip Phone
Subscribe
Spa 512g 1-line Ip Phone
Subscribe
Spa 514g 4-line Ip Phone
Subscribe
Spa 525g2 5-line Ip Phone
Subscribe
Spa 525g 5-line Ip Phone
Subscribe
|
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2014-3325 | The debug console interface on Cisco Small Business SPA300 and SPA500 phones does not properly perform authentication, which allows local users to execute arbitrary debug-shell commands, or read or modify data in memory or a filesystem, via direct access to this interface, aka Bug ID CSCun77435. |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
No history.
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: cisco
Published:
Updated: 2024-08-06T10:43:05.119Z
Reserved: 2014-05-07T00:00:00.000Z
Link: CVE-2014-3312
No data.
Status : Deferred
Published: 2014-07-09T11:07:01.493
Modified: 2025-04-12T10:46:40.837
Link: CVE-2014-3312
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD