logo

Hello? Are you talking on a Cisco SPA300 or SPA500 IP phone? Now's the time to junk 'em

ID: 0cb3aa4e-a471-5a1f-8965-96716cd293b0

STIX ID: report--0cb3aa4e-a471-5a1f-8965-96716cd293b0

Feed Name: The Register (Security)

Threat Score
75/100

Date Published: 2024-08-09

Date Updated: 2026-04-26

Author: Iain Thomson

...
...

Cisco disclosed five vulnerabilities affecting the web management interface of Small Business SPA300/SPA500 IP phones — three critical CVEs (CVSS 9.8) that allow unauthenticated remote buffer-overflow and root command execution via crafted HTTP requests, and two CVSS 7.8 issues that can cause denial of service. Cisco will not issue patches because the product line is end-of-life, leaving owners to replace affected hardware or run unsupported and vulnerable devices; no active exploitation has been reported so far.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.