Spa500 Firmware
Vendor:
First CVE: Mar 21, 2015 · Active for 11 years
5
Total CVEs
More Total CVEs than 79% of tracked products
1.3
Avg CVEs / Year
Higher CVE frequency than 58% of tracked products
7.5
Avg CVSS
Higher Avg CVSS than 52% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Spa500 Firmware over time
Volume of CVEsAvg CVSS Base Score
First CVE
Mar 21, 2015
11 years ago
Most Recent CVE
Feb 25, 2019
2,710 days ago
CVE Severity & Scoring
Spa500 Firmware5 CVEs
20%
80%
All CVEs353,173 CVEs
45%
40%
11%
MediumHigh
Attack Vector
Local0 (0.0%)
Network3 (60.0%)
Unknown2 (40.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low2 (40.0%)
High1 (20.0%)
Unknown2 (40.0%)
User Interaction
None2 (40.0%)
Unknown2 (40.0%)
Required1 (20.0%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None3 (60.0%)
Unknown2 (40.0%)
Top CVEs
Signals from CVEs in this product scope (5 CVEs).
5 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2017-12271HIGH A vulnerability in Cisco SPA300 and SPA500 Series IP Phones could allow an unauthenticated, remote attacker to execute unwanted actions on an affected device. The vulnerability is | Oct 19, 2017 | 8.8 | 25 | NO | NO |
CVE-2019-1683HIGH A vulnerability in the certificate handling component of the Cisco SPA112, SPA525, and SPA5X5 Series IP Phones could allow an unauthenticated, remote attacker to listen to or contr | Feb 25, 2019 | 7.4 | 24 | NO | NO |
CVE-2016-1469HIGH The HTTP framework on Cisco SPA300, SPA500, and SPA51x devices allows remote attackers to cause a denial of service (device outage) via a series of malformed HTTP requests, aka Bug | Sep 12, 2016 | 7.5 | 21 | NO | NO |
CVE-2015-6403HIGH The TFTP implementation on Cisco Small Business SPA30x, SPA50x, SPA51x phones 7.5.7 improperly validates firmware-image file integrity, which allows local users to load a Trojan ho | Dec 15, 2015 | 7.2 | 18 | NO | NO |
CVE-2015-0670MEDIUM The default configuration of Cisco Small Business IP phones SPA 300 7.5.5 and SPA 500 7.5.5 does not properly support authentication, which allows remote attackers to read audio-st | Mar 21, 2015 | 6.4 | 18 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (5 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (5 CVEs).
Media Mentions
Signals from CVEs in this product scope (5 CVEs).
Top CNAs Publishing CVEs For Spa500 Firmware
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 7.5.7 | 1 | 7.2 | 0.4% | 0 | 0 |
| 7.5.5 | 1 | 6.4 | 1.8% | 0 | 0 |
| 1.4.2 | 1 | 7.4 | 0.9% | 0 | 0 |