CVE-2019-15241 describes multiple vulnerabilities in Cisco SPA100 Series Analog Telephone Adapters (SPA112 and SPA122 models) that allow an authenticated, adjacent attacker to execute arbitrary code with elevated privileges. The vulnerabilities stem from improper input validation in the web-based management interface, which is enabled by default. This high-severity vulnerability (CVSS 8.0) requires an attacker to be on the same network segment and authenticate to the device, but does not require user interaction. While the potential impact is significant, leading to complete compromise of the device, there is currently no evidence of active exploitation, publicly available exploit code, or significant community discussion surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1.4.1CPE matchmatch criteria | cpe:2.3:o:cisco:spa112_firmware:*:*:*:*:*:*:*:* | ||
1.4.1CPE matchmatch criteria | cpe:2.3:o:cisco:spa112_firmware:1.4.1:-:*:*:*:*:*:* | ||
1.4.1CPE matchmatch criteria | cpe:2.3:o:cisco:spa112_firmware:1.4.1:sr1:*:*:*:*:*:* | ||
1.4.1CPE matchmatch criteria | cpe:2.3:o:cisco:spa112_firmware:1.4.1:sr2:*:*:*:*:*:* | ||
1.4.1CPE matchmatch criteria | cpe:2.3:o:cisco:spa112_firmware:1.4.1:sr3:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.3 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Cisco SPA100 Series Multiple Vulnerabilities
Oct 15, 2019Cisco SPA100 Series Multiple Vulnerabilities
Oct 15, 2019Cisco SPA100 Series Multiple Vulnerabilities
Oct 15, 2019Cisco SPA100 Series Multiple Vulnerabilities
Oct 15, 2019Cisco SPA100 Series Multiple Vulnerabilities
Oct 15, 2019Cisco SPA100 Series Multiple Vulnerabilities
Oct 15, 2019