CVE-2019-15258 – Cisco SPA100 Series Analog Telephone Adapters Web Management Interface Denial of Service Vulnerability
https://notcve.org/view.php?id=CVE-2019-15258
A vulnerability in the web-based management interface of Cisco SPA100 Series Analog Telephone Adapters (ATAs) could allow an authenticated, remote attacker to cause a denial of service condition on an affected device. The vulnerability is due to improper validation of user-supplied requests to the web-based management interface. An attacker could exploit this vulnerability by sending a crafted request to the web-based management interface of an affected device. A successful exploit could allow the attacker to cause the device to stop responding, requiring manual intervention for recovery. Una vulnerabilidad en la interfaz de administración basada en web de los dispositivos Cisco SPA100 Series Analog Telephone Adapters (ATAs), podría permitir a un atacante remoto autenticado causar una condición de denegación de servicio en un dispositivo afectado. • https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20191016-spa-webui-dos https://www.tenable.com/security/research/tra-2019-44 • CWE-399: Resource Management Errors CWE-476: NULL Pointer Dereference •
CVE-2019-15257 – Cisco SPA100 Series Analog Telephone Adapters Running Configuration Information Disclosure Vulnerability
https://notcve.org/view.php?id=CVE-2019-15257
A vulnerability in the web-based management interface of Cisco SPA100 Series Analog Telephone Adapters (ATAs) could allow an authenticated, remote attacker to access sensitive information on an affected device. The vulnerability is due to improper restrictions on configuration information. An attacker could exploit this vulnerability by sending a request to an affected device through the web-based management interface. A successful exploit could allow the attacker to return running configuration information that could also include sensitive information. Una vulnerabilidad en la interfaz de administración basada en web de los dispositivos Cisco SPA100 Series Analog Telephone Adapters (ATAs), podría permitir a un atacante remoto autenticado acceder a información confidencial en un dispositivo afectado. • https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20191016-spa-running-config https://www.tenable.com/security/research/tra-2019-44 • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor •
CVE-2019-15252 – Cisco SPA100 Series Analog Telephone Adapters Remote Code Execution Vulnerabilities
https://notcve.org/view.php?id=CVE-2019-15252
Multiple vulnerabilities in Cisco SPA100 Series Analog Telephone Adapters (ATAs) could allow an authenticated, adjacent attacker to execute arbitrary code with elevated privileges. The vulnerabilities are due to improper validation of user-supplied input to the web-based management interface. An attacker could exploit these vulnerabilities by authenticating to the web-based management interface and sending crafted requests to an affected device. A successful exploit could allow the attacker to execute arbitrary code with elevated privileges. Note: The web-based management interface is enabled by default. • https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20191016-spa-rce • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer •
CVE-2019-15251 – Cisco SPA100 Series Analog Telephone Adapters Remote Code Execution Vulnerabilities
https://notcve.org/view.php?id=CVE-2019-15251
Multiple vulnerabilities in Cisco SPA100 Series Analog Telephone Adapters (ATAs) could allow an authenticated, adjacent attacker to execute arbitrary code with elevated privileges. The vulnerabilities are due to improper validation of user-supplied input to the web-based management interface. An attacker could exploit these vulnerabilities by authenticating to the web-based management interface and sending crafted requests to an affected device. A successful exploit could allow the attacker to execute arbitrary code with elevated privileges. Note: The web-based management interface is enabled by default. • https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20191016-spa-rce • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer •
CVE-2019-15250 – Cisco SPA100 Series Analog Telephone Adapters Remote Code Execution Vulnerabilities
https://notcve.org/view.php?id=CVE-2019-15250
Multiple vulnerabilities in Cisco SPA100 Series Analog Telephone Adapters (ATAs) could allow an authenticated, adjacent attacker to execute arbitrary code with elevated privileges. The vulnerabilities are due to improper validation of user-supplied input to the web-based management interface. An attacker could exploit these vulnerabilities by authenticating to the web-based management interface and sending crafted requests to an affected device. A successful exploit could allow the attacker to execute arbitrary code with elevated privileges. Note: The web-based management interface is enabled by default. • https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20191016-spa-rce • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer •