Buffer overflow in Small Business SPA300 and Cisco Small Business SPA500 Series IP Phones - CVE-2024-20451
Published: August 8, 2024
Vulnerability identifier: #VU95556
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2024-20451
CWE-ID: CWE-119
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to a boundary error in the web-based management interface. A remote attacker can trigger memory corruption and cause a denial of service condition on the target system.
Affected software
Small Business SPA300
Cisco Small Business SPA500 Series IP Phones
Cisco Small Business SPA500 Series IP Phones
How to mitigate CVE-2024-20451
Cybersecurity Help is currently unaware of any official solution to address this vulnerability.