Cisco Phone Vulnerable To RCE Attacks – 07 May 2023

Cisco has disclosed a vulnerability in the web-based management interface of Cisco SPA112 2-Port phone adapters.

The addressed vulnerability could allow the remote attacker to execute arbitrary code on the affected device with full privileges by upgrading the affected device to a crafted version of the firmware.

The addressed vulnerability:

Cisco SPA112 2-Port Phone Adapters Command Execution (CVE-2023-20126):

  • CVSS: 9.8
  • Attack Vector: Network
  • Attack Complexity: Low
  • Privileges Required: None
  • User Interaction: None
  • Consequences: Gain Access

It should be highlighted that Cisco has announced that Cisco SPA112 2-Port phone adapters have entered the end-of-life process and will not release firmware updates to address this vulnerability.

Vulnerabilities

CVE-2023-20126

Mitigations

The enterprise should migrate to the Cisco ATA 190 Series Analog Telephone Adapter.

Cisco Security Advisory

References