Cisco Small Business SPA300 and SPA500 Series IP Phones Local Code Execution Vulnerability
BID:68465
Info
Cisco Small Business SPA300 and SPA500 Series IP Phones Local Code Execution Vulnerability
| Bugtraq ID: | 68465 |
| Class: | Input Validation Error |
| CVE: |
CVE-2014-3312 |
| Remote: | No |
| Local: | Yes |
| Published: | Jul 08 2014 12:00AM |
| Updated: | Jul 08 2014 12:00AM |
| Credit: | Cisco |
| Vulnerable: |
Cisco Small Business SPA500 Series IP Phones 0 Cisco Small Business SPA300 Series IP Phones 0 |
| Not Vulnerable: | |
Discussion
Cisco Small Business SPA300 and SPA500 Series IP Phones Local Code Execution Vulnerability
Cisco Small Business SPA300 and SPA500 Series IP Phones are prone to a local code-execution vulnerability.
A local attacker can leverage this issue to execute arbitrary code and gain access system memory with elevated privileges.
This issue is being tracked by Cisco Bug ID CSCun77435.
Cisco Small Business SPA300 and SPA500 Series IP Phones are prone to a local code-execution vulnerability.
A local attacker can leverage this issue to execute arbitrary code and gain access system memory with elevated privileges.
This issue is being tracked by Cisco Bug ID CSCun77435.
Exploit / POC
Cisco Small Business SPA300 and SPA500 Series IP Phones Local Code Execution Vulnerability
Attackers can use standard commands to exploit this issue.
Attackers can use standard commands to exploit this issue.
Solution / Fix
Cisco Small Business SPA300 and SPA500 Series IP Phones Local Code Execution Vulnerability
Solution:
Currently, we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently, we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
Cisco Small Business SPA300 and SPA500 Series IP Phones Local Code Execution Vulnerability
References:
References: