logo

Cisco warns of critical RCE zero-days in end of life IP phones

ID: 241efc45-8037-55b2-9497-e0ddb70353e8

STIX ID: report--241efc45-8037-55b2-9497-e0ddb70353e8

Feed Name: Bleeping Computer

Threat Score
78/100

Date Published: 2024-08-08

Date Updated: 2026-04-20

Author: Bill Toulas

...
...

Cisco disclosed five vulnerabilities in the web management interface of end-of-life SPA 300 and SPA 500 series IP phones — three critical unauthenticated remote-code-execution buffer overflows (CVE-2024-20450, CVE-2024-20452, CVE-2024-20454) and two high-severity denial-of-service flaws (CVE-2024-20451, CVE-2024-20453). Because these products are out of support and no fixes are available, Cisco recommends migrating to newer supported models and using the vendor's migration programs or contacting TAC for options.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.