CVE-2019-15251 describes multiple vulnerabilities in Cisco SPA100 Series Analog Telephone Adapters (ATAs), specifically affecting the SPA112 and SPA122 models. These flaws stem from improper input validation in the web-based management interface, which is enabled by default. An authenticated, adjacent attacker could exploit these vulnerabilities by sending crafted requests, leading to arbitrary code execution with elevated privileges. The vulnerability has a CVSS score of 8.0 (HIGH), indicating a significant risk. Exploitation requires authentication and adjacency, but the impact is high for confidentiality, integrity, and availability. Despite the high severity, there is no evidence of active exploitation, nor is there publicly available exploit code in Metasploit, Nuclei, or ExploitDB. Community discussion and media coverage for this CVE are minimal, with zero mentions across social media and news articles, which is typical for a large percentage of CVEs. The EPSS score is very low, suggesting a low probability of exploitation in the wild.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1.4.1CPE matchmatch criteria | cpe:2.3:o:cisco:spa112_firmware:*:*:*:*:*:*:*:* | ||
1.4.1CPE matchmatch criteria | cpe:2.3:o:cisco:spa112_firmware:1.4.1:-:*:*:*:*:*:* | ||
1.4.1CPE matchmatch criteria | cpe:2.3:o:cisco:spa112_firmware:1.4.1:sr1:*:*:*:*:*:* | ||
1.4.1CPE matchmatch criteria | cpe:2.3:o:cisco:spa112_firmware:1.4.1:sr2:*:*:*:*:*:* | ||
1.4.1CPE matchmatch criteria | cpe:2.3:o:cisco:spa112_firmware:1.4.1:sr3:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.3 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Cisco SPA100 Series Multiple Vulnerabilities
Oct 15, 2019Cisco SPA100 Series Multiple Vulnerabilities
Oct 15, 2019Cisco SPA100 Series Multiple Vulnerabilities
Oct 15, 2019Cisco SPA100 Series Multiple Vulnerabilities
Oct 15, 2019Cisco SPA100 Series Multiple Vulnerabilities
Oct 15, 2019Cisco SPA100 Series Multiple Vulnerabilities
Oct 15, 2019