Tech Analysis research archive

Tech Analysis discovers cross-site request forgery vulnerability in Cisco SPA300 and SPA500 Series IP phones, CVE-2017-12271

Originally published on techanalysis.com.au by Tech Analysis on under the title "Discovered a Cross-Site Request Forgery Vulnerability in Cisco SPA300 and SPA500 Series IP Phones. CVE-2017-12271"; first archived by the Internet Archive on . This page is a summary written to preserve the address and the record, not the original article text.

Tech Analysis is no longer trading. This website is maintained as the personal profile and research archive of its founder, Chris Watts, who now works at CyberCX. Earlier research remains attributed to Tech Analysis as originally published.

What was reported

On 18 October 2017 Cisco published an advisory for a cross-site request forgery (CSRF) vulnerability in its SPA300 and SPA500 Series IP phones with a default configuration, assigned CVE-2017-12271. In Cisco's words, a lack of CSRF protection could allow an unauthenticated, remote attacker to execute unwanted actions on an affected phone by tricking the user of a web application into performing an adverse action. Cisco gave it a CVSS v3.0 base score of 5.3 and no workaround was available.

Tech Analysis announced the finding on this page on 22 October 2017. It is the last Cisco credit published under the Tech Analysis name; Chris's later Cisco credit, for CVE-2023-20064, names CyberCX.

Primary sources

Attribution

Cisco's advisory states: "This vulnerability was reported to Cisco by Chris Watts of Tech Analysis."

See the full research index for all public vulnerability records credited to Chris Watts.