Tech Analysis research archive
Tech Analysis finds local code execution vulnerability in Cisco SPA300 and SPA500 Series IP phones, CVE-2014-3312
Tech Analysis is no longer trading. This website is maintained as the personal profile and research archive of its founder, Chris Watts, who now works at CyberCX. Earlier research remains attributed to Tech Analysis as originally published.
What was reported
On 9 July 2014 Cisco published a security notice for an authentication weakness in the debug console interface of its Small Business SPA300 and SPA500 Series IP phones, assigned CVE-2014-3312. In Cisco's words, insufficient authentication in the debug console could allow an unauthenticated, local attacker to access the debug shell and file system of the device; the attacker must have local access to the targeted phone. SPA500 firmware 7.5(.4) and prior and SPA300 firmware 7.5(.5) and prior were listed as affected, Cisco gave it a CVSS v2 base score of 6.9, and no software update was available at the time of the notice.
Tech Analysis announced the finding on this page on 21 July 2014 as a vulnerability found by Chris Watts of Tech Analysis. This is a local-access issue; some later secondary reporting described it as remote, which Cisco's notice does not support.
Primary sources
- Cisco: Cisco Small Business SPA300 and SPA500 Series IP Phones Local Code Execution Vulnerability (first published 9 July 2014)
- CVE-2014-3312 on cve.org
- Archived copy of the original Tech Analysis article (Internet Archive)
Attribution
Cisco's currently published notice for CVE-2014-3312 does not display a researcher credit. Attribution to Chris Watts of Tech Analysis is supported by the original Tech Analysis announcement preserved by the Internet Archive and by iTnews (Cisco confirms IP phone eavesdropping flaw, 22 March 2015).
See the full research index for all public vulnerability records credited to Chris Watts.