CVE-2015-6403 describes an improper firmware image integrity validation vulnerability in the TFTP implementation of Cisco Small Business SPA30x, SPA50x, and SPA51x phones running version 7.5.7. This flaw allows a local attacker with shell access to load a malicious firmware image, effectively installing a Trojan horse. With a CVSS score of 7.2, this vulnerability is considered highly severe due to its local attack vector and potential for complete compromise of confidentiality, integrity, and availability. There is no evidence of active exploitation, and no public exploit code is available in Metasploit, Nuclei, or ExploitDB, with minimal community discussion and media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
7.5.7CPE matchmatch criteria | cpe:2.3:o:cisco:spa500_firmware:7.5.7:*:*:*:*:*:*:* | ||
7.5.7CPE matchmatch criteria | cpe:2.3:o:cisco:spa300_firmware:7.5.7:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:L/AC:L/Au:N/C:C/I:C/A:C
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.5 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.