8.8
CVSSv3

CVE-2017-12271

Published: 19/10/2017 Updated: 27/06/2023
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
CVSS v3 Base Score: 8.8 | Impact Score: 5.9 | Exploitability Score: 2.8
VMScore: 605
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

A vulnerability in Cisco SPA300 and SPA500 Series IP Phones could allow an unauthenticated, remote malicious user to execute unwanted actions on an affected device. The vulnerability is due to a lack of cross-site request forgery (CSRF) protection. An attacker could exploit this vulnerability by tricking the user of a web application into executing an adverse action. Cisco Bug IDs: CSCuz88421, CSCuz91356, CSCve56308.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

cisco spa300 firmware

cisco spa500 firmware

Vendor Advisories

A vulnerability in Cisco SPA300 and SPA500 Series IP Phones could allow an unauthenticated, remote attacker to execute unwanted actions on an affected device The vulnerability is due to a lack of cross-site request forgery (CSRF) protection An attacker could exploit this vulnerability by tricking the user of a web application into executing an a ...