
CVE-2019-15244 – Cisco SPA100 Series Analog Telephone Adapters Remote Code Execution Vulnerabilities
https://notcve.org/view.php?id=CVE-2019-15244
16 Oct 2019 — Multiple vulnerabilities in Cisco SPA100 Series Analog Telephone Adapters (ATAs) could allow an authenticated, adjacent attacker to execute arbitrary code with elevated privileges. The vulnerabilities are due to improper validation of user-supplied input to the web-based management interface. An attacker could exploit these vulnerabilities by authenticating to the web-based management interface and sending crafted requests to an affected device. A successful exploit could allow the attacker to execute arbit... • https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20191016-spa-rce • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer •

CVE-2019-15243 – Cisco SPA100 Series Analog Telephone Adapters Remote Code Execution Vulnerabilities
https://notcve.org/view.php?id=CVE-2019-15243
16 Oct 2019 — Multiple vulnerabilities in Cisco SPA100 Series Analog Telephone Adapters (ATAs) could allow an authenticated, adjacent attacker to execute arbitrary code with elevated privileges. The vulnerabilities are due to improper validation of user-supplied input to the web-based management interface. An attacker could exploit these vulnerabilities by authenticating to the web-based management interface and sending crafted requests to an affected device. A successful exploit could allow the attacker to execute arbit... • https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20191016-spa-rce • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer •

CVE-2019-15242 – Cisco SPA100 Series Analog Telephone Adapters Remote Code Execution Vulnerabilities
https://notcve.org/view.php?id=CVE-2019-15242
16 Oct 2019 — Multiple vulnerabilities in Cisco SPA100 Series Analog Telephone Adapters (ATAs) could allow an authenticated, adjacent attacker to execute arbitrary code with elevated privileges. The vulnerabilities are due to improper validation of user-supplied input to the web-based management interface. An attacker could exploit these vulnerabilities by authenticating to the web-based management interface and sending crafted requests to an affected device. A successful exploit could allow the attacker to execute arbit... • https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20191016-spa-rce • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer •

CVE-2019-15241 – Cisco SPA100 Series Analog Telephone Adapters Remote Code Execution Vulnerabilities
https://notcve.org/view.php?id=CVE-2019-15241
16 Oct 2019 — Multiple vulnerabilities in Cisco SPA100 Series Analog Telephone Adapters (ATAs) could allow an authenticated, adjacent attacker to execute arbitrary code with elevated privileges. The vulnerabilities are due to improper validation of user-supplied input to the web-based management interface. An attacker could exploit these vulnerabilities by authenticating to the web-based management interface and sending crafted requests to an affected device. A successful exploit could allow the attacker to execute arbit... • https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20191016-spa-rce • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer •

CVE-2019-15240 – Cisco SPA100 Series Analog Telephone Adapters Remote Code Execution Vulnerabilities
https://notcve.org/view.php?id=CVE-2019-15240
16 Oct 2019 — Multiple vulnerabilities in Cisco SPA100 Series Analog Telephone Adapters (ATAs) could allow an authenticated, adjacent attacker to execute arbitrary code with elevated privileges. The vulnerabilities are due to improper validation of user-supplied input to the web-based management interface. An attacker could exploit these vulnerabilities by authenticating to the web-based management interface and sending crafted requests to an affected device. A successful exploit could allow the attacker to execute arbit... • https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20191016-spa-rce • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer •

CVE-2019-12708 – Cisco SPA100 Series Analog Telephone Adapters Administrative Credentials Information Disclosure Vulnerability
https://notcve.org/view.php?id=CVE-2019-12708
16 Oct 2019 — A vulnerability in the web-based management interface of Cisco SPA100 Series Analog Telephone Adapters (ATAs) could allow an authenticated, remote attacker to access sensitive information on an affected device. The vulnerability is due to unsafe handling of user credentials. An attacker could exploit this vulnerability by viewing portions of the web-based management interface of an affected device. A successful exploit could allow the attacker to access administrative credentials and potentially gain elevat... • https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20191016-spa-credentials • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor •

CVE-2019-12704 – Cisco SPA100 Series Analog Telephone Adapters Web-Based Management Interface File Disclosure Vulnerability
https://notcve.org/view.php?id=CVE-2019-12704
16 Oct 2019 — A vulnerability in the web-based management interface of Cisco SPA100 Series Analog Telephone Adapters (ATAs) could allow an authenticated, remote attacker to view the contents of arbitrary files on an affected device. The vulnerability is due to improper input validation in the web-based management interface. An attacker could exploit this vulnerability by sending a crafted request to the web-based management interface of an affected device. A successful exploit could allow the attacker to retrieve the con... • https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20191016-spa-ui-disclosure • CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') CWE-200: Exposure of Sensitive Information to an Unauthorized Actor •

CVE-2019-12703 – Cisco SPA122 ATA with Router Devices DHCP Services Cross-Site Scripting Vulnerability
https://notcve.org/view.php?id=CVE-2019-12703
16 Oct 2019 — A vulnerability in the web-based management interface of Cisco SPA122 ATA with Router Devices could allow an unauthenticated, adjacent attacker to conduct cross-site scripting attacks. The vulnerability is due to insufficient validation of user-supplied input by the web-based management interface of the affected software. An attacker could exploit this vulnerability by sending malicious input to the affected software through crafted DHCP requests, and then persuading a user to click a crafted link. A succes... • https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20191016-spa-dhcp-xss • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVE-2019-12702 – Cisco SPA100 Series Analog Telephone Adapters Reflected Cross-Site Scripting Vulnerability
https://notcve.org/view.php?id=CVE-2019-12702
16 Oct 2019 — A vulnerability in the web-based management interface of Cisco SPA100 Series Analog Telephone Adapters (ATAs) could allow an authenticated, remote attacker to conduct cross-site scripting attacks. The vulnerability is due to insufficient validation of user-supplied input by the web-based management interface of the affected software. An attacker could exploit this vulnerability by persuading a user to click a crafted link. A successful exploit could allow the attacker to execute arbitrary script code in the... • https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20191016-spa-reflected-xss • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •