Tech Analysis research archive
Tech Analysis discovers Cisco IP phone firmware image upload vulnerability, CVE-2015-6403
Tech Analysis is no longer trading. This website is maintained as the personal profile and research archive of its founder, Chris Watts, who now works at CyberCX. Earlier research remains attributed to Tech Analysis as originally published.
What was reported
On 9 December 2015 Cisco published an advisory for a firmware image upload vulnerability in its SPA30X, SPA50X and SPA51X Series IP phones, assigned CVE-2015-6403. In Cisco's words, insufficient integrity checks on firmware images could allow an unauthenticated, local attacker to load arbitrary firmware onto the phone; exploitation requires access to the device's local shell. Cisco gave it a CVSS v2 base score of 4.9 with a local attack vector.
Tech Analysis announced the finding on this page on 21 December 2015. This is a local-access weakness and should not be described as unauthenticated remote code execution.
Primary sources
- Cisco: Multiple Cisco IP Phones Firmware Image Upload Vulnerability (first published 9 December 2015)
- CVE-2015-6403 on cve.org
- Archived copy of the original Tech Analysis article (Internet Archive)
Attribution
Cisco's advisory states: "Cisco would like to thank security researcher Chris Watts for discovering and reporting this vulnerability." The advisory names the researcher without an organisation; the original Tech Analysis announcement connects it to Tech Analysis.
See the full research index for all public vulnerability records credited to Chris Watts.