Tech Analysis research archive
Tech Analysis discovers cross-site request forgery vulnerability in Cisco SPA300 and SPA500 Series IP phones, CVE-2017-12271
Tech Analysis is no longer trading. This website is maintained as the personal profile and research archive of its founder, Chris Watts, who now works at CyberCX. Earlier research remains attributed to Tech Analysis as originally published.
What was reported
On 18 October 2017 Cisco published an advisory for a cross-site request forgery (CSRF) vulnerability in its SPA300 and SPA500 Series IP phones with a default configuration, assigned CVE-2017-12271. In Cisco's words, a lack of CSRF protection could allow an unauthenticated, remote attacker to execute unwanted actions on an affected phone by tricking the user of a web application into performing an adverse action. Cisco gave it a CVSS v3.0 base score of 5.3 and no workaround was available.
Tech Analysis announced the finding on this page on 22 October 2017. It is the last Cisco credit published under the Tech Analysis name; Chris's later Cisco credit, for CVE-2023-20064, names CyberCX.
Primary sources
- Cisco: Cisco SPA300 and SPA500 Series IP Phones Cross-Site Request Forgery Vulnerability (first published 18 October 2017)
- CVE-2017-12271 on cve.org
- Archived copy of the original Tech Analysis article (Internet Archive)
Attribution
Cisco's advisory states: "This vulnerability was reported to Cisco by Chris Watts of Tech Analysis."
See the full research index for all public vulnerability records credited to Chris Watts.