// For flags

CVE-2015-0670

 

Severity Score

6.4
*CVSS v2

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

0
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

The default configuration of Cisco Small Business IP phones SPA 300 7.5.5 and SPA 500 7.5.5 does not properly support authentication, which allows remote attackers to read audio-stream data or originate telephone calls via a crafted XML request, aka Bug ID CSCuo52482.

La configuración por defecto de Cisco Small Business IP phones SPA 300 7.5.5 y SPA 500 7.5.5 no soporta adecuadamente autenticación, lo que permite a atacantes remotos leer flujo de datos de audio o originar llamadas de teléfono a través de una petición XML modificada, también conocido como Bug ID CSCuo52482.

*Credits: N/A
CVSS Scores
Attack Vector
Network
Attack Complexity
Low
Authentication
None
Confidentiality
Partial
Integrity
Partial
Availability
None
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2015-01-07 CVE Reserved
  • 2015-03-21 CVE Published
  • 2023-03-07 EPSS Updated
  • 2024-08-06 CVE Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
  • ---------- First Exploit
CWE
  • CWE-287: Improper Authentication
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Cisco
Search vendor "Cisco"
Spa500 Firmware
Search vendor "Cisco" for product "Spa500 Firmware"
7.5.5
Search vendor "Cisco" for product "Spa500 Firmware" and version "7.5.5"
-
Affected
in Cisco
Search vendor "Cisco"
Spa 501g 8-line Ip Phone
Search vendor "Cisco" for product "Spa 501g 8-line Ip Phone"
*-
Affected
Cisco
Search vendor "Cisco"
Spa500 Firmware
Search vendor "Cisco" for product "Spa500 Firmware"
7.5.5
Search vendor "Cisco" for product "Spa500 Firmware" and version "7.5.5"
-
Affected
in Cisco
Search vendor "Cisco"
Spa 502g 1-line Ip Phone
Search vendor "Cisco" for product "Spa 502g 1-line Ip Phone"
*-
Affected
Cisco
Search vendor "Cisco"
Spa500 Firmware
Search vendor "Cisco" for product "Spa500 Firmware"
7.5.5
Search vendor "Cisco" for product "Spa500 Firmware" and version "7.5.5"
-
Affected
in Cisco
Search vendor "Cisco"
Spa 504g 4-line Ip Phone
Search vendor "Cisco" for product "Spa 504g 4-line Ip Phone"
*-
Affected
Cisco
Search vendor "Cisco"
Spa500 Firmware
Search vendor "Cisco" for product "Spa500 Firmware"
7.5.5
Search vendor "Cisco" for product "Spa500 Firmware" and version "7.5.5"
-
Affected
in Cisco
Search vendor "Cisco"
Spa 508g 8-line Ip Phone
Search vendor "Cisco" for product "Spa 508g 8-line Ip Phone"
*-
Affected
Cisco
Search vendor "Cisco"
Spa500 Firmware
Search vendor "Cisco" for product "Spa500 Firmware"
7.5.5
Search vendor "Cisco" for product "Spa500 Firmware" and version "7.5.5"
-
Affected
in Cisco
Search vendor "Cisco"
Spa 509g 12-line Ip Phone
Search vendor "Cisco" for product "Spa 509g 12-line Ip Phone"
*-
Affected
Cisco
Search vendor "Cisco"
Spa500 Firmware
Search vendor "Cisco" for product "Spa500 Firmware"
7.5.5
Search vendor "Cisco" for product "Spa500 Firmware" and version "7.5.5"
-
Affected
in Cisco
Search vendor "Cisco"
Spa 512g 1-line Ip Phone
Search vendor "Cisco" for product "Spa 512g 1-line Ip Phone"
*-
Affected
Cisco
Search vendor "Cisco"
Spa500 Firmware
Search vendor "Cisco" for product "Spa500 Firmware"
7.5.5
Search vendor "Cisco" for product "Spa500 Firmware" and version "7.5.5"
-
Affected
in Cisco
Search vendor "Cisco"
Spa 514g 4-line Ip Phone
Search vendor "Cisco" for product "Spa 514g 4-line Ip Phone"
*-
Affected
Cisco
Search vendor "Cisco"
Spa500 Firmware
Search vendor "Cisco" for product "Spa500 Firmware"
7.5.5
Search vendor "Cisco" for product "Spa500 Firmware" and version "7.5.5"
-
Affected
in Cisco
Search vendor "Cisco"
Spa 525g 5-line Ip Phone
Search vendor "Cisco" for product "Spa 525g 5-line Ip Phone"
*-
Affected
Cisco
Search vendor "Cisco"
Spa500 Firmware
Search vendor "Cisco" for product "Spa500 Firmware"
7.5.5
Search vendor "Cisco" for product "Spa500 Firmware" and version "7.5.5"
-
Affected
in Cisco
Search vendor "Cisco"
Spa 525g2 5-line Ip Phone
Search vendor "Cisco" for product "Spa 525g2 5-line Ip Phone"
*-
Affected
Cisco
Search vendor "Cisco"
Spa300 Firmware
Search vendor "Cisco" for product "Spa300 Firmware"
7.5.5
Search vendor "Cisco" for product "Spa300 Firmware" and version "7.5.5"
-
Affected
in Cisco
Search vendor "Cisco"
Spa 301 1 Line Ip Phone
Search vendor "Cisco" for product "Spa 301 1 Line Ip Phone"
*-
Affected
Cisco
Search vendor "Cisco"
Spa300 Firmware
Search vendor "Cisco" for product "Spa300 Firmware"
7.5.5
Search vendor "Cisco" for product "Spa300 Firmware" and version "7.5.5"
-
Affected
in Cisco
Search vendor "Cisco"
Spa 302d
Search vendor "Cisco" for product "Spa 302d"
*-
Affected
Cisco
Search vendor "Cisco"
Spa300 Firmware
Search vendor "Cisco" for product "Spa300 Firmware"
7.5.5
Search vendor "Cisco" for product "Spa300 Firmware" and version "7.5.5"
-
Affected
in Cisco
Search vendor "Cisco"
Spa 302dkit
Search vendor "Cisco" for product "Spa 302dkit"
*-
Affected
Cisco
Search vendor "Cisco"
Spa300 Firmware
Search vendor "Cisco" for product "Spa300 Firmware"
7.5.5
Search vendor "Cisco" for product "Spa300 Firmware" and version "7.5.5"
-
Affected
in Cisco
Search vendor "Cisco"
Spa 303 3 Line Ip Phone
Search vendor "Cisco" for product "Spa 303 3 Line Ip Phone"
*-
Affected