CVE-2017-12271
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
A vulnerability in Cisco SPA300 and SPA500 Series IP Phones could allow an unauthenticated, remote attacker to execute unwanted actions on an affected device. The vulnerability is due to a lack of cross-site request forgery (CSRF) protection. An attacker could exploit this vulnerability by tricking the user of a web application into executing an adverse action. Cisco Bug IDs: CSCuz88421, CSCuz91356, CSCve56308.
Una vulnerabilidad en Cisco SPA300 y SPA500 Series IP Phones podría permitir que un atacante remoto no autenticado ejecute acciones no deseadas en un dispositivo afectado. La vulnerabilidad se debe a la ausencia de medidas de protección contra ataques de Cross-Site Request Forgery (CSRF). Un atacante podría explotar esta vulnerabilidad engañando al usuario de una aplicación web para que ejecute una acción adversa. Cisco Bug IDs: CSCuz88421, CSCuz91356, CSCve56308.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2017-08-03 CVE Reserved
- 2017-10-19 CVE Published
- 2023-03-12 EPSS Updated
- 2024-08-05 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-352: Cross-Site Request Forgery (CSRF)
CAPEC
References (3)
URL | Tag | Source |
---|---|---|
http://www.securityfocus.com/bid/101524 | Third Party Advisory | |
http://www.securitytracker.com/id/1039621 | Third Party Advisory |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20171018-spa | 2023-06-27 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Cisco Search vendor "Cisco" | Spa300 Firmware Search vendor "Cisco" for product "Spa300 Firmware" | <= 7.5.5 Search vendor "Cisco" for product "Spa300 Firmware" and version " <= 7.5.5" | - |
Affected
| in | Cisco Search vendor "Cisco" | Spa300 Series Ip Phone Search vendor "Cisco" for product "Spa300 Series Ip Phone" | - | - |
Safe
|
Cisco Search vendor "Cisco" | Spa300 Firmware Search vendor "Cisco" for product "Spa300 Firmware" | <= 7.5.5 Search vendor "Cisco" for product "Spa300 Firmware" and version " <= 7.5.5" | - |
Affected
| in | Cisco Search vendor "Cisco" | Spa500 Series Ip Phone Search vendor "Cisco" for product "Spa500 Series Ip Phone" | - | - |
Safe
|
Cisco Search vendor "Cisco" | Spa500 Firmware Search vendor "Cisco" for product "Spa500 Firmware" | <= 7.5.5 Search vendor "Cisco" for product "Spa500 Firmware" and version " <= 7.5.5" | - |
Affected
| in | Cisco Search vendor "Cisco" | Spa300 Series Ip Phone Search vendor "Cisco" for product "Spa300 Series Ip Phone" | - | - |
Safe
|
Cisco Search vendor "Cisco" | Spa500 Firmware Search vendor "Cisco" for product "Spa500 Firmware" | <= 7.5.5 Search vendor "Cisco" for product "Spa500 Firmware" and version " <= 7.5.5" | - |
Affected
| in | Cisco Search vendor "Cisco" | Spa500 Series Ip Phone Search vendor "Cisco" for product "Spa500 Series Ip Phone" | - | - |
Safe
|