Description
A vulnerability in the web-based management interface of Cisco ATA 190 Series Multiplatform Analog Telephone Adapter firmware could allow an authenticated, local attacker with low privileges to view passwords on an affected device. This vulnerability is due to incorrect sanitization of HTML content from an affected device. A successful exploit could allow the attacker to view passwords that belong to other users.
Scores
CVSS v3
5.5
EPSS
0.0012
EPSS Percentile
31.2%
Attack Vector
LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
partial
Details
CWE
CWE-522
CWE-257
CWE-922
Status
published
Products (2)
cisco/ata_191_firmware
< 12.0.2
cisco/ata_192_firmware
< 11.2.5
Published
Oct 16, 2024
Tracked Since
Feb 18, 2026