CVE-2023-20218

MEDIUM

Cisco SPA500 Series ATAs - Authenticated Stored Cross-Site Scripting

Title source: llm
STIX 2.1

Description

A vulnerability in web-based management interface of Cisco SPA500 Series Analog Telephone Adapters (ATAs) could allow an authenticated, remote attacker to to modify a web page in the context of a user's browser. This vulnerability is due to insufficient validation of user-supplied input by the web-based management interface of the affected software. An attacker could exploit this vulnerability by persuading a user to click a crafted link. A successful exploit could allow the attacker to alter the contents of a web page to redirect the user to potentially malicious websites, or the attacker could use this vulnerability to conduct further client-side attacks. Cisco will not release software updates that address this vulnerability. {{value}} ["%7b%7bvalue%7d%7d"])}]]

Scores

CVSS v3 5.8
EPSS 0.0013
EPSS Percentile 31.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-80 CWE-79
Status published
Products (12)
cisco/spa500ds_firmware
cisco/spa500s_firmware
cisco/spa501g_firmware
cisco/spa502g_firmware
cisco/spa504g_firmware
cisco/spa508g_firmware
cisco/spa509g_firmware
cisco/spa512g_firmware
cisco/spa514g_firmware
cisco/spa525_firmware
... and 2 more
Published Aug 03, 2023
Tracked Since Feb 18, 2026