Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2019-1683— Cisco SPA112, SPA525, and SPA5x5 Series IP Phones Certificate Validation Vulnerability

Quick assessment

Affected
Cisco Cisco Small Business SPA500 Series IP Phones
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Cisco SPA112 Series等都是美国思科(Cisco)公司的产品。Cisco SPA112 Series是一款SPA112系列IP电话。SPA525 Series是一款SPA525系列IP电话。SPA5X5 Series是一款SPA5X5系列IP电话。 Cisco SPA112、SPA525和SPA5X5 Series中的证书处理组件存在信任管理问题漏洞,该漏洞源于程序没有正确验证服务器证书。远程攻击者可通过构建恶意的服务器证书利用该漏洞监听或控制部分被安全传输层协议(TLS)加密的会话初始协

AI Predicted 7.5 Difficulty: Easy EPSS 0.87% · P57

Possible ATT&CK Techniques 2 AI

T1198 T1557 · Adversary-in-the-Middle
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2019-1683

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Cisco SPA112, SPA525, and SPA5x5 Series IP Phones Certificate Validation Vulnerability
Source: CVE Program / CVE List V5
Vulnerability Description
A vulnerability in the certificate handling component of the Cisco SPA112, SPA525, and SPA5X5 Series IP Phones could allow an unauthenticated, remote attacker to listen to or control some aspects of a Transport Level Security (TLS)-encrypted Session Initiation Protocol (SIP) conversation. The vulnerability is due to the improper validation of server certificates. An attacker could exploit this vulnerability by crafting a malicious server certificate to present to the client. An exploit could allow an attacker to eavesdrop on TLS-encrypted traffic and potentially route or redirect calls initiated by an affected device. Affected software include version 7.6.2 of the Cisco Small Business SPA525 Series IP Phones and Cisco Small Business SPA5X5 Series IP Phones and version 1.4.2 of the Cisco Small Business SPA500 Series IP Phones and Cisco Small Business SPA112 Series IP Phones.
Source: CVE Program / CVE List V5
CVSS Information
N/A
Source: CVE Program / CVE List V5
Vulnerability Type
证书验证不恰当
Source: CVE Program / CVE List V5
Vulnerability Title
Cisco SPA112、SPA525和SPA5X5 Series 信任管理问题漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Cisco SPA112 Series等都是美国思科(Cisco)公司的产品。Cisco SPA112 Series是一款SPA112系列IP电话。SPA525 Series是一款SPA525系列IP电话。SPA5X5 Series是一款SPA5X5系列IP电话。 Cisco SPA112、SPA525和SPA5X5 Series中的证书处理组件存在信任管理问题漏洞,该漏洞源于程序没有正确验证服务器证书。远程攻击者可通过构建恶意的服务器证书利用该漏洞监听或控制部分被安全传输层协议(TLS)加密的会话初始协
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

II. Public POCs for CVE-2019-1683

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2019-1683

登录查看更多情报信息。

Vendor Advisories for CVE-2019-1683 (2)

IV. Related Vulnerabilities

V. Comments for CVE-2019-1683

No comments yet


Leave a comment