← Back

CVE-2011-2545

nvd nist
Published: Jun 13, 2012Modified: Apr 29, 2026

JSON object

Loading...
4.3
Vector
AV:N/AC:M/Au:N/C:N/I:P/A:N
Exploitability: 8.6 / Impact: 2.9
Source: NVD

Description

Cross-site scripting (XSS) vulnerability in the SIP implementation on the Cisco SPA8000 and SPA8800 before 6.1.11, SPA2102 and SPA3102 before 5.2.13, and SPA 500 series IP phones before 7.4.9 allows remote attackers to inject arbitrary web script or HTML via the FROM field of an INVITE message, aka Bug IDs CSCtr27277, CSCtr27256, CSCtr27274, and CSCtr14715.

Affected (30)

18 products
Spa8800 Ip Telephony Gateway
Spa2102 Phone Adapter With Router
Spa3102 Voice Gateway With Router
Spa 500 Series Ip Phone Firmware
Spa 501g 8 Line Ip Phone
Spa 502g 1 Line Ip Phone
Spa 504g 4 Line Ip Phone
Spa 508g 8 Line Ip Phone
Spa 509g 12 Line Ip Phone
Spa 512g 1 Line Ip Phone
Spa 514g 4 Line Ip Phone
Spa 525g2 5 Line Ip Phone
Spa 525g 5 Line Ip Phone
Configuration A
4 vulnerable
Configuration B
2 vulnerable
Vulnerable SoftwareAffected Versions
Up to 6.1.7
All versions
Configuration C
5 vulnerable
Configuration D
4 vulnerable
Configuration E
15 vulnerable

References (2)

Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory

Timeline

No history available yet.