A vulnerability in the web-based management interface of Cisco ATA 190 Series Analog Telephone Adapter firmware could allow an unauthenticated, remote attacker to view or delete the configuration or change the firmware on an affected device.

This vulnerability is due to a lack of authentication on specific HTTP endpoints. An attacker could exploit this vulnerability by browsing to a specific URL. A successful exploit could allow the attacker to view or delete the configuration or change the firmware.
Advisories
Source ID Title
EUVD EUVD EUVD-2024-18173 A vulnerability in the web-based management interface of Cisco ATA 190 Series Analog Telephone Adapter firmware could allow an unauthenticated, remote attacker to view or delete the configuration or change the firmware on an affected device. This vulnerability is due to a lack of authentication on specific HTTP endpoints. An attacker could exploit this vulnerability by browsing to a specific URL. A successful exploit could allow the attacker to view or delete the configuration or change the firmware.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Wed, 23 Oct 2024 03:30:00 +0900

Type Values Removed Values Added
First Time appeared Cisco ata 191
Cisco ata 191 Firmware
Cisco ata 192
Cisco ata 192 Firmware
CPEs cpe:2.3:h:cisco:ata_191:-:*:*:*:multiplatform:*:*:*
cpe:2.3:h:cisco:ata_191:-:*:*:*:on-premises:*:*:*
cpe:2.3:h:cisco:ata_192:-:*:*:*:multiplatform:*:*:*
cpe:2.3:o:cisco:ata_191_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:cisco:ata_192_firmware:*:*:*:*:*:*:*:*
Vendors & Products Cisco ata 191
Cisco ata 191 Firmware
Cisco ata 192
Cisco ata 192 Firmware

Thu, 17 Oct 2024 05:15:00 +0900

Type Values Removed Values Added
First Time appeared Cisco
Cisco ata 190 Firmware
CPEs cpe:2.3:o:cisco:ata_190_firmware:11.1.0:*:*:*:*:*:*:*
cpe:2.3:o:cisco:ata_190_firmware:11.1.0_msr1:*:*:*:*:*:*:*
cpe:2.3:o:cisco:ata_190_firmware:11.1.0_msr2:*:*:*:*:*:*:*
cpe:2.3:o:cisco:ata_190_firmware:11.1.0_msr3:*:*:*:*:*:*:*
cpe:2.3:o:cisco:ata_190_firmware:11.1.0_msr4:*:*:*:*:*:*:*
cpe:2.3:o:cisco:ata_190_firmware:11.2.1:*:*:*:*:*:*:*
cpe:2.3:o:cisco:ata_190_firmware:11.2.2:*:*:*:*:*:*:*
cpe:2.3:o:cisco:ata_190_firmware:11.2.2_msr1:*:*:*:*:*:*:*
cpe:2.3:o:cisco:ata_190_firmware:11.2.3:*:*:*:*:*:*:*
cpe:2.3:o:cisco:ata_190_firmware:11.2.4:*:*:*:*:*:*:*
cpe:2.3:o:cisco:ata_190_firmware:12.0.1:*:*:*:*:*:*:*
cpe:2.3:o:cisco:ata_190_firmware:12.0.1_sr1:*:*:*:*:*:*:*
cpe:2.3:o:cisco:ata_190_firmware:12.0.1_sr2:*:*:*:*:*:*:*
cpe:2.3:o:cisco:ata_190_firmware:12.0.1_sr3:*:*:*:*:*:*:*
cpe:2.3:o:cisco:ata_190_firmware:12.0.1_sr4:*:*:*:*:*:*:*
cpe:2.3:o:cisco:ata_190_firmware:12.0.1_sr5:*:*:*:*:*:*:*
Vendors & Products Cisco
Cisco ata 190 Firmware
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 17 Oct 2024 01:30:00 +0900

Type Values Removed Values Added
Description A vulnerability in the web-based management interface of Cisco ATA 190 Series Analog Telephone Adapter firmware could allow an unauthenticated, remote attacker to view or delete the configuration or change the firmware on an affected device. This vulnerability is due to a lack of authentication on specific HTTP endpoints. An attacker could exploit this vulnerability by browsing to a specific URL. A successful exploit could allow the attacker to view or delete the configuration or change the firmware.
Title Cisco ATA 190 Series Analog Telephone Adapter Software Vulnerabilities
Weaknesses CWE-78
References
Metrics cvssV3_1

{'score': 8.2, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:L'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: cisco

Published:

Updated: 2024-10-16T19:38:32.175Z

Reserved: 2023-11-08T15:08:07.679Z

Link: CVE-2024-20458

cve-icon Vulnrichment

Updated: 2024-10-16T19:30:10.860Z

cve-icon NVD

Status : Analyzed

Published: 2024-10-16T17:15:14.423

Modified: 2024-10-22T18:03:09.777

Link: CVE-2024-20458

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses