CVE Vulnerabilities

CVE-2014-3312

Improper Authentication

Published: Jul 09, 2014 | Modified: Apr 12, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
6.9 MEDIUM
AV:L/AC:M/Au:N/C:C/I:C/A:C
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

The debug console interface on Cisco Small Business SPA300 and SPA500 phones does not properly perform authentication, which allows local users to execute arbitrary debug-shell commands, or read or modify data in memory or a filesystem, via direct access to this interface, aka Bug ID CSCun77435.

Weakness

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

Affected Software

NameVendorStart VersionEnd Version
Spa_301_1_line_ip_phoneCisco**
Spa_303_3_line_ip_phoneCisco**
Spa_501g_8-line_ip_phoneCisco**
Spa_502g_1-line_ip_phoneCisco**
Spa_504g_4-line_ip_phoneCisco**
Spa_508g_8-line_ip_phoneCisco**
Spa_509g_12-line_ip_phoneCisco**
Spa_512g_1-line_ip_phoneCisco**
Spa_514g_4-line_ip_phoneCisco**
Spa_525g_5-line_ip_phoneCisco**
Spa_525g2_5-line_ip_phoneCisco**
Spa901_1-line_ip_phoneCisco**
Spa922_1-line_ip_phone_with_1-port_ethernetCisco**
Spa941_4-line_ip_phone_with_1-port_ethernetCisco**
Spa942_4-line_ip_phone_with_2-port_switchCisco**
Spa962_6-line_ip_phone_with_2-port_switchCisco**

Potential Mitigations

References