Vulnerability Details CVE-2019-15258
A vulnerability in the web-based management interface of Cisco SPA100 Series Analog Telephone Adapters (ATAs) could allow an authenticated, remote attacker to cause a denial of service condition on an affected device. The vulnerability is due to improper validation of user-supplied requests to the web-based management interface. An attacker could exploit this vulnerability by sending a crafted request to the web-based management interface of an affected device. A successful exploit could allow the attacker to cause the device to stop responding, requiring manual intervention for recovery.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.005
EPSS Ranking 63.3%
CVSS Severity
CVSS v3 Score 6.5
CVSS v2 Score 6.8
Products affected by CVE-2019-15258
-
-
-
cpe:2.3:o:cisco:spa112_firmware:*
-
cpe:2.3:o:cisco:spa112_firmware:1.4.1
-
cpe:2.3:o:cisco:spa122_firmware:*
-
cpe:2.3:o:cisco:spa122_firmware:1.4.1