Authentication Flaw in Cisco Small Business SPA300 and SPA500 Phones
CVE-2014-3312
Currently unrated
Key Information:
- Vendor
Cisco
- Status
- Vendor
- CVE Published:
- 9 July 2014
What is CVE-2014-3312?
The debug console interface on Cisco Small Business SPA300 and SPA500 phones is susceptible to an authentication bypass. This flaw permits local users to execute arbitrary debug-shell commands or access sensitive memory or filesystem data by directly interacting with the interface. This exposure could potentially lead to unauthorized actions and serious implications for device security.