Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2015-6403


The TFTP implementation on Cisco Small Business SPA30x, SPA50x, SPA51x phones 7.5.7 improperly validates firmware-image file integrity, which allows local users to load a Trojan horse image by leveraging shell access, aka Bug ID CSCut67400.


Published

2015-12-15T05:59:04.853

Last Modified

2025-04-12T10:46:40.837

Status

Deferred

Source

[email protected]

Severity

CVSSv2: 7.2 (HIGH)

CVSSv2 Vector

AV:L/AC:L/Au:N/C:C/I:C/A:C

  • Access Vector: LOCAL
  • Access Complexity: LOW
  • Authentication: NONE
  • Confidentiality Impact: COMPLETE
  • Integrity Impact: COMPLETE
  • Availability Impact: COMPLETE
Exploitability Score

3.9

Impact Score

10.0

Weaknesses
  • Type: Primary
    CWE-20

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Operating System cisco spa500_firmware 7.5.7 Yes
Hardware cisco spa_500ds - No
Hardware cisco spa_500s - No
Hardware cisco spa_501g - No
Hardware cisco spa_502g - No
Hardware cisco spa_504g - No
Hardware cisco spa_508g - No
Hardware cisco spa_509g - No
Hardware cisco spa_512g - No
Hardware cisco spa_514g - No
Hardware cisco spa_525g2 - No
Operating System cisco spa300_firmware 7.5.7 Yes
Hardware cisco spa_301 - No
Hardware cisco spa_303 - No

References