Cisco has revealed several severe security issues impacting its Small Business SPA300 and SPA500 Series IP Phones. These vulnerabilities could enable attackers to execute arbitrary commands with root access or induce denial of service (DoS) conditions.
The identified flaws, cataloged as CVE-2024-20450, CVE-2024-20451, CVE-2024-20452, CVE-2024-20453, and CVE-2024-20454, reside within the web-based management interface of these devices. The most critical vulnerabilities (CVE-2024-20450, CVE-2024-20452, and CVE-2024-20454) allow unauthorized remote attackers to execute arbitrary commands on the device’s operating system with root privileges.
These issues are due to inadequate validation of incoming HTTP packets, which could lead to a buffer overflow. An attacker could exploit this by sending a specially crafted HTTP request to a vulnerable device. Additionally, CVE-2024-20451 and CVE-2024-20453 could let unauthorized remote attackers cause unexpected reboots, leading to a denial of service.
These vulnerabilities have been rated as Critical, with a CVSS Base Score of 9.8 for the command execution flaws and 7.5 for the DoS issues.
Cisco has announced that it will not provide software updates for these vulnerabilities because the affected products are now at the end of their life cycle. The company recommends checking the end-of-life notices and considering replacement options.
Currently, there are no available workarounds for these vulnerabilities. Organizations using Cisco Small Business SPA300 and SPA500 Series IP Phones should evaluate their risk and consider migrating to supported devices.
These vulnerabilities were reported to Cisco by Aidan of BAE Systems Digital Intelligence. Cisco has not seen any public exploitation or malicious activity related to these vulnerabilities as of now.



