MEDIUM · 6.9

CVE-2014-3312

The debug console interface on Cisco Small Business SPA300 and SPA500 phones does not properly perform authentication, which allows local users to execute arbitrary debug-shell commands, or read or mo...

Vulnerability Description

The debug console interface on Cisco Small Business SPA300 and SPA500 phones does not properly perform authentication, which allows local users to execute arbitrary debug-shell commands, or read or modify data in memory or a filesystem, via direct access to this interface, aka Bug ID CSCun77435.

CVSS Score

6.9

MEDIUM

AV:L/AC:M/Au:N/C:C/I:C/A:C
Confidentiality
COMPLETE
Integrity
COMPLETE
Availability
COMPLETE

Affected Products

VendorProductVersions
CiscoSpa 301 1 Line Ip PhoneAll versions
CiscoSpa 303 3 Line Ip PhoneAll versions
CiscoSpa 501G 8-Line Ip PhoneAll versions
CiscoSpa 502G 1-Line Ip PhoneAll versions
CiscoSpa 504G 4-Line Ip PhoneAll versions
CiscoSpa 508G 8-Line Ip PhoneAll versions
CiscoSpa 509G 12-Line Ip PhoneAll versions
CiscoSpa 512G 1-Line Ip PhoneAll versions
CiscoSpa 514G 4-Line Ip PhoneAll versions
CiscoSpa 525G 5-Line Ip PhoneAll versions
CiscoSpa 525G2 5-Line Ip PhoneAll versions
CiscoSpa901 1-Line Ip PhoneAll versions
CiscoSpa922 1-Line Ip Phone With 1-Port EthernetAll versions
CiscoSpa941 4-Line Ip Phone With 1-Port EthernetAll versions
CiscoSpa942 4-Line Ip Phone With 2-Port SwitchAll versions
CiscoSpa962 6-Line Ip Phone With 2-Port SwitchAll versions

Related Weaknesses (CWE)

References

FAQ

What is CVE-2014-3312?

CVE-2014-3312 is a vulnerability with a CVSS score of 6.9 (MEDIUM). The debug console interface on Cisco Small Business SPA300 and SPA500 phones does not properly perform authentication, which allows local users to execute arbitrary debug-shell commands, or read or mo...

How severe is CVE-2014-3312?

CVE-2014-3312 has been rated MEDIUM with a CVSS base score of 6.9/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2014-3312?

Check the references section above for vendor advisories and patch information. Affected products include: Cisco Spa 301 1 Line Ip Phone, Cisco Spa 303 3 Line Ip Phone, Cisco Spa 501G 8-Line Ip Phone, Cisco Spa 502G 1-Line Ip Phone, Cisco Spa 504G 4-Line Ip Phone.