CVE-2015-6403
Severity CVSS v4.0:
Pending analysis
Type:
CWE-20
Input Validation
Publication date:
15/12/2015
Last modified:
12/04/2025
Description
The TFTP implementation on Cisco Small Business SPA30x, SPA50x, SPA51x phones 7.5.7 improperly validates firmware-image file integrity, which allows local users to load a Trojan horse image by leveraging shell access, aka Bug ID CSCut67400.
Impact
Base Score 2.0
7.20
Severity 2.0
HIGH
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:o:cisco:spa500_firmware:7.5.7:*:*:*:*:*:*:* | ||
| cpe:2.3:h:cisco:spa_500ds:-:*:*:*:*:*:*:* | ||
| cpe:2.3:h:cisco:spa_500s:-:*:*:*:*:*:*:* | ||
| cpe:2.3:h:cisco:spa_501g:-:*:*:*:*:*:*:* | ||
| cpe:2.3:h:cisco:spa_502g:-:*:*:*:*:*:*:* | ||
| cpe:2.3:h:cisco:spa_504g:-:*:*:*:*:*:*:* | ||
| cpe:2.3:h:cisco:spa_508g:-:*:*:*:*:*:*:* | ||
| cpe:2.3:h:cisco:spa_509g:-:*:*:*:*:*:*:* | ||
| cpe:2.3:h:cisco:spa_512g:-:*:*:*:*:*:*:* | ||
| cpe:2.3:h:cisco:spa_514g:-:*:*:*:*:*:*:* | ||
| cpe:2.3:h:cisco:spa_525g2:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:cisco:spa300_firmware:7.5.7:*:*:*:*:*:*:* | ||
| cpe:2.3:h:cisco:spa_301:-:*:*:*:*:*:*:* | ||
| cpe:2.3:h:cisco:spa_303:-:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page
References to Advisories, Solutions, and Tools
- http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20151209-ipp
- http://www.securityfocus.com/bid/78739
- http://www.securitytracker.com/id/1034376
- http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20151209-ipp
- http://www.securityfocus.com/bid/78739
- http://www.securitytracker.com/id/1034376



