MEDIUM · 6.6

CVE-2019-15959

A vulnerability in Cisco Small Business SPA500 Series IP Phones could allow a physically proximate attacker to execute arbitrary commands on the device. The vulnerability is due to the presence of dev...

Vulnerability Description

A vulnerability in Cisco Small Business SPA500 Series IP Phones could allow a physically proximate attacker to execute arbitrary commands on the device. The vulnerability is due to the presence of development testing and verification scripts that remained on the device. An attacker could exploit this vulnerability by accessing the physical interface of a device and inserting a USB storage device. A successful exploit could allow the attacker to execute scripts on the device in an elevated security context.

CVSS Score

6.6

MEDIUM

CVSS:3.1/AV:P/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Attack Vector
PHYSICAL
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
HIGH
Integrity
HIGH
Availability
HIGH

Affected Products

VendorProductVersions
CiscoSpa500 Series Ip Phones Firmware<= 7.5.7\(5\)
CiscoSpa500Ds-
CiscoSpa500S-
CiscoSpa501G-
CiscoSpa502G-
CiscoSpa504G-
CiscoSpa512G-
CiscoSpa514G-
CiscoSpa525G-
CiscoSpa525G2-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2019-15959?

CVE-2019-15959 is a vulnerability with a CVSS score of 6.6 (MEDIUM). A vulnerability in Cisco Small Business SPA500 Series IP Phones could allow a physically proximate attacker to execute arbitrary commands on the device. The vulnerability is due to the presence of dev...

How severe is CVE-2019-15959?

CVE-2019-15959 has been rated MEDIUM with a CVSS base score of 6.6/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2019-15959?

Check the references section above for vendor advisories and patch information. Affected products include: Cisco Spa500 Series Ip Phones Firmware, Cisco Spa500Ds, Cisco Spa500S, Cisco Spa501G, Cisco Spa502G.