CVE-2019-1923
Summary
| CVE | CVE-2019-1923 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2019-07-17 21:15:00 UTC |
| Updated | 2020-10-16 15:14:00 UTC |
| Description | A vulnerability in Cisco Small Business SPA500 Series IP Phones could allow a physically proximate attacker to execute arbitrary commands on the device. The vulnerability is due to improper input validation in the device configuration interface. An attacker could exploit this vulnerability by accessing the configuration interface, which may require a password, and then accessing the device's physical interface and inserting a USB storage device. A successful exploit could allow the attacker to execute arbitrary commands on the device in an elevated security context. At the time of publication, this vulnerability affected Cisco Small Business SPA500 Series IP Phones firmware releases 7.6.2SR5 and prior. |
Risk And Classification
Problem Types: CWE-20
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Hardware | Cisco | Spa500ds | - | All | All | All |
| Hardware | Cisco | Spa500ds | - | All | All | All |
| Operating System | Cisco | Spa500ds Firmware | All | All | All | All |
| Hardware | Cisco | Spa500s | - | All | All | All |
| Hardware | Cisco | Spa500s | - | All | All | All |
| Operating System | Cisco | Spa500s Firmware | All | All | All | All |
| Hardware | Cisco | Spa501g | - | All | All | All |
| Hardware | Cisco | Spa501g | - | All | All | All |
| Operating System | Cisco | Spa501g Firmware | All | All | All | All |
| Hardware | Cisco | Spa502g | - | All | All | All |
| Hardware | Cisco | Spa502g | - | All | All | All |
| Operating System | Cisco | Spa502g Firmware | All | All | All | All |
| Hardware | Cisco | Spa504g | - | All | All | All |
| Hardware | Cisco | Spa504g | - | All | All | All |
| Operating System | Cisco | Spa504g Firmware | All | All | All | All |
| Hardware | Cisco | Spa508g | - | All | All | All |
| Hardware | Cisco | Spa508g | - | All | All | All |
| Operating System | Cisco | Spa508g Firmware | All | All | All | All |
| Hardware | Cisco | Spa509g | - | All | All | All |
| Hardware | Cisco | Spa509g | - | All | All | All |
| Operating System | Cisco | Spa509g Firmware | All | All | All | All |
| Hardware | Cisco | Spa512g | - | All | All | All |
| Hardware | Cisco | Spa512g | - | All | All | All |
| Operating System | Cisco | Spa512g Firmware | All | All | All | All |
| Hardware | Cisco | Spa514g | - | All | All | All |
| Hardware | Cisco | Spa514g | - | All | All | All |
| Operating System | Cisco | Spa514g Firmware | All | All | All | All |
| Hardware | Cisco | Spa525g2 | - | All | All | All |
| Hardware | Cisco | Spa525g2 | - | All | All | All |
| Operating System | Cisco | Spa525g2 Firmware | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Cisco Small Business SPA500 Series IP Phones Local Command Execution Vulnerability | CISCO | tools.cisco.com | Vendor Advisory |
| 109294 | BID | www.securityfocus.com | Third Party Advisory, VDB Entry |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.