Cisco Releases Security Advisory for ATA 190 Series Analog Telephone Adapter
Eight vulnerabilities are addressed in this advisory rated as high severity by Cisco
Summary
Eight vulnerabilities are addressed in this advisory rated as high severity by Cisco
Threat details
Introduction
Cisco has released a high severity advisory concerning Cisco ATA 190 Series Analog Telephone Adapters, which enable analogue devices, such as phones, fax machines and paging systems to act as IP devices. These eight vulnerabilities centre around authentication, cross-site request forgery, cross-site scripting, command injection, information disclosure, denial-of-service (DoS), and privilege escalation.
Successful exploit could allow a remote attacker to delete or change the configuration, execute commands as the root user, conduct a cross-site scripting (XSS) attack against a user of the interface, view passwords, conduct a cross-site request forgery attack, or reboot the device.
Remediation advice
Affected organisations are encouraged to review Cisco's ATA 190 Series Analog Telephone Adapter Firmware Vulnerabilities advisory cisco-sa-ata19x-multi-RDTEqRsy for more information.
Definitive source of threat updates
CVE Vulnerabilities
Last edited: 17 October 2024 3:51 pm