CVE Vulnerabilities

CVE-2014-3312

Improper Authentication

Published: Jul 09, 2014 | Modified: Aug 29, 2017
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
6.9 MEDIUM
AV:L/AC:M/Au:N/C:C/I:C/A:C
RedHat/V2
RedHat/V3
Ubuntu

The debug console interface on Cisco Small Business SPA300 and SPA500 phones does not properly perform authentication, which allows local users to execute arbitrary debug-shell commands, or read or modify data in memory or a filesystem, via direct access to this interface, aka Bug ID CSCun77435.

Weakness

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

Affected Software

Name Vendor Start Version End Version
Spa_301_1_line_ip_phone Cisco * *
Spa_303_3_line_ip_phone Cisco * *
Spa_501g_8-line_ip_phone Cisco * *
Spa_502g_1-line_ip_phone Cisco * *
Spa_504g_4-line_ip_phone Cisco * *
Spa_508g_8-line_ip_phone Cisco * *
Spa_509g_12-line_ip_phone Cisco * *
Spa_512g_1-line_ip_phone Cisco * *
Spa_514g_4-line_ip_phone Cisco * *
Spa_525g_5-line_ip_phone Cisco * *
Spa_525g2_5-line_ip_phone Cisco * *
Spa901_1-line_ip_phone Cisco * *
Spa922_1-line_ip_phone_with_1-port_ethernet Cisco * *
Spa941_4-line_ip_phone_with_1-port_ethernet Cisco * *
Spa942_4-line_ip_phone_with_2-port_switch Cisco * *
Spa962_6-line_ip_phone_with_2-port_switch Cisco * *

Potential Mitigations

References