A vulnerability in Cisco SPA300 and SPA500 Series IP Phones could allow an unauthenticated, remote attacker to execute unwanted actions on an affected device. The vulnerability is due to a lack of cross-site request forgery (CSRF) protection. An attacker could exploit this vulnerability by tricking the user of a web application into executing an adverse action. Cisco Bug IDs: CSCuz88421, CSCuz91356, CSCve56308.
2017-10-19T08:29:00.343
2025-04-20T01:37:25.860
Deferred
CVSSv3.1: 8.8 (HIGH)
AV:N/AC:M/Au:N/C:P/I:P/A:P
8.6
6.4
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Operating System | cisco | spa300_firmware | ≤ 7.5.5 | Yes |
Operating System | cisco | spa500_firmware | ≤ 7.5.5 | Yes |
Hardware | cisco | spa300_series_ip_phone | - | No |
Hardware | cisco | spa500_series_ip_phone | - | No |