CVE-2023-20126
Cisco SPA112 2-Port Phone Adapters Remote Command Execution Vulnerability
Vexday Risk Score
60Attention
SSVC decision (CISA)
Attend
PoC available → attend closely
CVSS 9.8EPSS 38.1%KEV nãoPoC públicaPatch referenciado
Lifecycle
04 May 2023Published on NVD
17 May 2023Public PoC
Recommendation: Plan a near-term fix — a public PoC already exists.
A vulnerability in the web-based management interface of Cisco SPA112 2-Port Phone Adapters could allow an unauthenticated, remote attacker to execute arbitrary code on an affected device. This vulnerability is due to a missing authentication process within the firmware upgrade function. An attacker could exploit this vulnerability by upgrading an affected device to a crafted version of firmware. A successful exploit could allow the attacker to execute arbitrary code on the affected device with full privileges. Cisco has not released firmware updates to address this vulnerability.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Affected products
Cisco · Cisco Small Business IP Phonespublic PoCs found — 1
githubgithub.com/fullspectrumdev/RancidCrisco★ 24⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.
Want to know if your infrastructure is exposed to this?
Talk to TrueHacking →