The default configuration of Cisco Small Business IP phones SPA 300 7.5.5 and SPA 500 7.5.5 does not properly support authentication, which allows remote attackers to read audio-stream data or originate telephone calls via a crafted XML request, aka Bug ID CSCuo52482.
Project Subscriptions
| Vendors | Products |
|---|---|
|
Cisco
Subscribe
|
Spa300 Firmware
Subscribe
Spa500 Firmware
Subscribe
Spa 301 1 Line Ip Phone
Subscribe
Spa 302d
Subscribe
Spa 302dkit
Subscribe
Spa 303 3 Line Ip Phone
Subscribe
Spa 501g 8-line Ip Phone
Subscribe
Spa 502g 1-line Ip Phone
Subscribe
Spa 504g 4-line Ip Phone
Subscribe
Spa 508g 8-line Ip Phone
Subscribe
Spa 509g 12-line Ip Phone
Subscribe
Spa 512g 1-line Ip Phone
Subscribe
Spa 514g 4-line Ip Phone
Subscribe
Spa 525g2 5-line Ip Phone
Subscribe
Spa 525g 5-line Ip Phone
Subscribe
|
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2015-0683 | The default configuration of Cisco Small Business IP phones SPA 300 7.5.5 and SPA 500 7.5.5 does not properly support authentication, which allows remote attackers to read audio-stream data or originate telephone calls via a crafted XML request, aka Bug ID CSCuo52482. |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
No history.
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: cisco
Published:
Updated: 2024-08-06T04:17:32.586Z
Reserved: 2015-01-07T00:00:00.000Z
Link: CVE-2015-0670
No data.
Status : Deferred
Published: 2015-03-21T01:59:01.560
Modified: 2025-04-12T10:46:40.837
Link: CVE-2015-0670
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD