← Vulnerability feed

Vulnerability record · CVE-2019-15240 · published 16 October 2019

CVE-2019-15240: Cisco spa112 firmware memory buffer overflow vulnerability

Cisco · Spa112 Firmware

Multiple vulnerabilities in Cisco SPA100 Series Analog Telephone Adapters (ATAs) could allow an authenticated, adjacent attacker to execute arbitrary code with elevated privileges. The vulnerabilities are due to improper validation of user-supplied input to the web-based management interface. An attacker could exploit these vulnerabilities by authenticating to the web-based management interface and sending crafted requests to an affected device. A successful exploit could allow the attacker to execute arbitrary code with elevated privileges. Note: The web-based management interface is enabled by default.

8.0 CVSS 3.1 High EPSS 0.58% · top 54.6% CWE-119 · Memory buffer overflow
8.0CVSS 3.1 base score, v2 5.2
0.58%EPSS exploitation probability, 30 days
NoNot in CISA KEV
2Affected product versions listed by NVD
2References
17 Jun 2026Last modified by NVD

Description

Multiple vulnerabilities in Cisco SPA100 Series Analog Telephone Adapters (ATAs) could allow an authenticated, adjacent attacker to execute arbitrary code with elevated privileges. The vulnerabilities are due to improper validation of user-supplied input to the web-based management interface. An attacker could exploit these vulnerabilities by authenticating to the web-based management interface and sending crafted requests to an affected device. A successful exploit could allow the attacker to execute arbitrary code with elevated privileges. Note: The web-based management interface is enabled by default.

CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Affected products

2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2019-15240 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2023-20126Cisco spa112 firmware missing authentication for critical function vulnerabilityA vulnerability in the web-based management interface of Cisco SPA112 2-Port Phone Adapters could allow an unauthenticated, remote attacker to execut…EPSS 37%8.0CVE-2019-15249Cisco spa112 firmware memory buffer overflow vulnerabilityMultiple vulnerabilities in Cisco SPA100 Series Analog Telephone Adapters (ATAs) could allow an authenticated, adjacent attacker to execute arbitrary…EPSS 0.58%8.0CVE-2019-15250Cisco spa112 firmware memory buffer overflow vulnerabilityMultiple vulnerabilities in Cisco SPA100 Series Analog Telephone Adapters (ATAs) could allow an authenticated, adjacent attacker to execute arbitrary…EPSS 0.58%8.0CVE-2019-15251Cisco spa112 firmware memory buffer overflow vulnerabilityMultiple vulnerabilities in Cisco SPA100 Series Analog Telephone Adapters (ATAs) could allow an authenticated, adjacent attacker to execute arbitrary…EPSS 0.58%8.0CVE-2019-15252Cisco spa112 firmware memory buffer overflow vulnerabilityMultiple vulnerabilities in Cisco SPA100 Series Analog Telephone Adapters (ATAs) could allow an authenticated, adjacent attacker to execute arbitrary…EPSS 0.58%8.0CVE-2019-15241Cisco spa112 firmware memory buffer overflow vulnerabilityMultiple vulnerabilities in Cisco SPA100 Series Analog Telephone Adapters (ATAs) could allow an authenticated, adjacent attacker to execute arbitrary…EPSS 0.58%8.0CVE-2019-15242Cisco spa112 firmware memory buffer overflow vulnerabilityMultiple vulnerabilities in Cisco SPA100 Series Analog Telephone Adapters (ATAs) could allow an authenticated, adjacent attacker to execute arbitrary…EPSS 0.58%8.0CVE-2019-15243Cisco spa112 firmware memory buffer overflow vulnerabilityMultiple vulnerabilities in Cisco SPA100 Series Analog Telephone Adapters (ATAs) could allow an authenticated, adjacent attacker to execute arbitrary…EPSS 0.58%

Source: NIST National Vulnerability Database (record CVE-2019-15240), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.