Skip to main content

Cisco Releases Security Advisory for ATA 190 Series Analog Telephone Adapter

Eight vulnerabilities are addressed in this advisory rated as high severity by Cisco 

Report a cyber attack: call 0300 303 5222 or email [email protected]

Summary

Eight vulnerabilities are addressed in this advisory rated as high severity by Cisco 


Affected platforms

The following platforms are known to be affected:

Threat details

Introduction

Cisco has released a high severity advisory concerning Cisco ATA 190 Series Analog Telephone Adapters, which enable analogue devices, such as phones, fax machines and paging systems to act as IP devices. These eight vulnerabilities centre around authentication, cross-site request forgery, cross-site scripting, command injection, information disclosure, denial-of-service (DoS), and privilege escalation.

Successful exploit could allow a remote attacker to delete or change the configuration, execute commands as the root user, conduct a cross-site scripting (XSS) attack against a user of the interface, view passwords, conduct a cross-site request forgery attack, or reboot the device.


Remediation advice

Affected organisations are encouraged to review Cisco's ATA 190 Series Analog Telephone Adapter Firmware Vulnerabilities advisory cisco-sa-ata19x-multi-RDTEqRsy for more information.



CVE Vulnerabilities

Last edited: 17 October 2024 3:51 pm