CVE-2019-12708 is a sensitive information disclosure vulnerability affecting Cisco SPA100 Series Analog Telephone Adapters (SPA112 and SPA122). An authenticated, remote attacker can exploit unsafe handling of user credentials within the web-based management interface to access administrative credentials, potentially leading to elevated privileges. With a CVSS score of 6.5 (Medium), this vulnerability has a low attack complexity and no user interaction required, but it does require prior authentication. There is no evidence of active exploitation, publicly available exploit code, or significant community discussion surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1.4.1CPE matchmatch criteria | cpe:2.3:o:cisco:spa112_firmware:*:*:*:*:*:*:*:* | ||
1.4.1CPE matchmatch criteria | cpe:2.3:o:cisco:spa112_firmware:1.4.1:-:*:*:*:*:*:* | ||
1.4.1CPE matchmatch criteria | cpe:2.3:o:cisco:spa112_firmware:1.4.1:sr1:*:*:*:*:*:* | ||
1.4.1CPE matchmatch criteria | cpe:2.3:o:cisco:spa112_firmware:1.4.1:sr2:*:*:*:*:*:* | ||
1.4.1CPE matchmatch criteria | cpe:2.3:o:cisco:spa112_firmware:1.4.1:sr3:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Cisco SPA100 Series Multiple Vulnerabilities
Oct 15, 2019Cisco SPA100 Series Multiple Vulnerabilities
Oct 15, 2019Cisco SPA100 Series Multiple Vulnerabilities
Oct 15, 2019Cisco SPA100 Series Multiple Vulnerabilities
Oct 15, 2019Cisco SPA100 Series Multiple Vulnerabilities
Oct 15, 2019Cisco SPA100 Series Multiple Vulnerabilities
Oct 15, 2019