Vulnslist

Cisco vulnerabilities by product, model, software, and advisory.

CVE-2015-0670

The default configuration of Cisco Small Business IP phones SPA 300 7.5.5 and SPA 500 7.5.5 does not properly support authentication, which allows remote attackers to read audio-stream data or originate telephone calls via a crafted XML request, aka Bug ID CSCuo52482.

SeverityMEDIUM
CVSS6.4
CWECWE-287
KEV
Published
Modified

Related Products

Product Advisory Evidence
Cisco Small Business SPA500 Series IP Phones Cisco-SA-20150319-CVE-2015-0670 Cisco OpenVuln