CVE-2019-15959 MEDIUM

CVE-2019-15959: Cisco Small Business SPA500 Series IP Phones Local Script Execution Vulnerability

Vendor Cisco
Product Cisco SPA525G2 5-line IP Phone
Weakness CWE-20 · Input validation
Published September 23, 2020
Last update November 13, 2024

CVSS base score

6.6/10
Attack vector Physical
Attack complexity Low
Privileges required Low
User interaction None
Confidentiality High
Integrity High

CVSS vector

CVSS:3.0/AV:P/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

What the vulnerability does

01Description

A vulnerability in Cisco Small Business SPA500 Series IP Phones could allow a physically proximate attacker to execute arbitrary commands on the device. The vulnerability is due to the presence of development testing and verification scripts that remained on the device. An attacker could exploit this vulnerability by accessing the physical interface of a device and inserting a USB storage device. A successful exploit could allow the attacker to execute scripts on the device in an elevated security context.

Key dates

02Disclosure timeline

September 23, 2020 CVE published
November 13, 2024 Record updated