Skip to main content

Eight vulnerabilities are addressed in this advisory rated as high severity by Cisco

Summary

Eight vulnerabilities are addressed in this advisory rated as high severity by Cisco 

Affected platforms

The following platforms are known to be affected:

Threat details

Introduction

Cisco has released a high severity advisory concerning Cisco ATA 190 Series Analog Telephone Adapters, which enable analogue devices, such as phones, fax machines and paging systems to act as IP devices. These eight vulnerabilities centre around authentication, cross-site request forgery, cross-site scripting, command injection, information disclosure, denial-of-service (DoS), and privilege escalation.

Successful exploit could allow a remote attacker to delete or change the configuration, execute commands as the root user, conduct a cross-site scripting (XSS) attack against a user of the interface, view passwords, conduct a cross-site request forgery attack, or reboot the device.

Remediation advice

Affected organisations are encouraged to review Cisco's ATA 190 Series Analog Telephone Adapter Firmware Vulnerabilities advisory cisco-sa-ata19x-multi-RDTEqRsy for more information.

Definitive source of threat updates

CVE Vulnerabilities

Last edited: 17 October 2024 3:51 pm