CVE-2011-2545

UnknownEPSS 0.94%

Last modified

CVE-2011-2545 is a vulnerability of currently unknown severity. Cross-site scripting (XSS) vulnerability in the SIP implementation on the Cisco SPA8000 and SPA8800 before 6.1.11, SPA2102 and SPA3102 before 5.2.13, and SPA 500 series IP phones before 7.4.9 allows remote attackers to inject arbitrary web script or HTML via the FROM field of an INVITE message, aka Bug IDs CSCtr27277, CSCtr27256, CSCtr27274, and CSCtr14715.. EPSS estimates a 0.94% chance of exploitation in the next 30 days.

Description

Cross-site scripting (XSS) vulnerability in the SIP implementation on the Cisco SPA8000 and SPA8800 before 6.1.11, SPA2102 and SPA3102 before 5.2.13, and SPA 500 series IP phones before 7.4.9 allows remote attackers to inject arbitrary web script or HTML via the FROM field of an INVITE message, aka Bug IDs CSCtr27277, CSCtr27256, CSCtr27274, and CSCtr14715.

Metrics

EPSS Probability
0.94%

56.4th percentile

Probability of exploitation in the next 30 days. Learn more

Weakness Enumeration

Affected Software

VendorProductVersions
CiscoSpa8000 8-Port Ip Telephony Gateway Firmware<= 6.1.10
CiscoSpa8000 8-Port Ip Telephony Gateway Firmware5.1.12
CiscoSpa8000 8-Port Ip Telephony Gateway Firmware6.1.3
CiscoSpa8000 8-Port Ip Telephony GatewayAll versions
CiscoSpa8800 8-Port Ip Telephony Gateway Firmware<= 6.1.7
CiscoSpa8800 Ip Telephony GatewayAll versions
CiscoSpa2102 Phone Adapter With Router Firmware<= 5.2.12
CiscoSpa2102 Phone Adapter With Router Firmware5.2.3
CiscoSpa2102 Phone Adapter With Router Firmware5.2.5
CiscoSpa2102 Phone Adapter With Router Firmware5.2.10
CiscoSpa2102 Phone Adapter With RouterAll versions
CiscoSpa3102 Voice Gateway With Router Firmware<= 5.1.10
CiscoSpa3102 Voice Gateway With Router Firmware3.3.6
CiscoSpa3102 Voice Gateway With Router Firmware5.1.7
CiscoSpa3102 Voice Gateway With RouterAll versions
CiscoSpa 500 Series Ip Phone Firmware<= 7.4.8
CiscoSpa 500 Series Ip Phone Firmware7.3.7
CiscoSpa 500 Series Ip Phone Firmware7.4.3
CiscoSpa 500 Series Ip Phone Firmware7.4.4
CiscoSpa 500 Series Ip Phone Firmware7.4.6
CiscoSpa 500 Series Ip Phone Firmware7.4.7
CiscoSpa 501g 8-Line Ip PhoneAll versions
CiscoSpa 502g 1-Line Ip PhoneAll versions
CiscoSpa 504g 4-Line Ip PhoneAll versions
CiscoSpa 508g 8-Line Ip PhoneAll versions
CiscoSpa 509g 12-Line Ip PhoneAll versions
CiscoSpa 512g 1-Line Ip PhoneAll versions
CiscoSpa 514g 4-Line Ip PhoneAll versions
CiscoSpa 525g 5-Line Ip PhoneAll versions
CiscoSpa 525g2 5-Line Ip PhoneAll versions

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2011-2545?
Cross-site scripting (XSS) vulnerability in the SIP implementation on the Cisco SPA8000 and SPA8800 before 6.1.11, SPA2102 and SPA3102 before 5.2.13, and SPA 500 series IP phones before 7.4.9 allows remote attackers to inject arbitrary web script or HTML via the FROM field of an INVITE message, aka Bug IDs CSCtr27277, CSCtr27256, CSCtr27274, and CSCtr14715.
How severe is CVE-2011-2545?
Severity scoring for CVE-2011-2545 is pending analysis. The EPSS model estimates a 0.94% probability of exploitation in the next 30 days.
How do I fix CVE-2011-2545?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2011-2545?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST