https://www.theregister.com/2023/05/05/cisco_phone_adapter_vulnerabilitty/ # # Sign in / up The Register(r) -- Biting the hand that feeds IT # # # Topics Security Security All SecurityCyber-crimePatchesResearchCSO (X) Off-Prem Off-Prem All Off-PremEdge + IoTChannelPaaS + IaaSSaaS (X) On-Prem On-Prem All On-PremSystemsStorageNetworksHPCPersonal Tech (X) Software Software All SoftwareAI + MLApplicationsDatabasesDevOpsOSesVirtualization (X) Offbeat Offbeat All OffbeatDebatesColumnistsScienceGeek's GuideBOFHLegalBootnotesSite NewsAbout Us (X) Special Features Special Features Spotlight on Databases Defense Tech Week Energy Efficient Datacenters Spotlight on RSA Vendor Voice Vendor Voice Vendor Voice All Vendor VoiceAmazon Web Services (AWS) Business TransformationDDN ElasticGoogle Cloud for StartupsIntel vPro (X) Resources Resources Whitepapers Webinars Newsletters [cso] CSO 5 comment bubble on white Dump these insecure phone adapters because we're not fixing them, says Cisco 5 comment bubble on white Security hole ranks 9.8 out of 10 in severity, 0 out of 10 in patch availability icon Jeff Burt Fri 5 May 2023 // 21:04 UTC # There is a critical security flaw in a Cisco phone adapter, and the business technology giant says the only step to take is dumping the hardware and migrating to new kit. In an advisory, Cisco this week warned about the vulnerability in the SPA112 2-Port Adapter that, if exploited, could allow a remote attacker to essentially take control of a compromised device by seizing full privileges and executing arbitrary code. The flaw, tracked as CVE-2023-20126, is rated as "critical," with a base score of 9.8 out of 10. [cso] Adding to the problem is the fact that the adapter reached its end of life in June 2020, and while the last date to extend or renew a service contract for the product isn't until August 2024, Cisco said in the advisory it will not release firmware updates to address the flaw and there are no workarounds. [cso] [cso] "Customers are encouraged to migrate to a Cisco ATA 190 Series Analog Telephone Adapter," the manufacturer wrote in its advisory. The Register has asked Cisco for more information, and will update the story if a response comes in. [cso] The flaw is in the web-based management interface for the two-port adapter, which is used by organizations to connect analog phones and fax machines (please don't ask us to explain what those are) to voice-over-IP systems without having to upgrade them. The vulnerability stems from a missing authentication process in the firmware upgrade function, according to Cisco. "This vulnerability is due to a missing authentication process within the firmware upgrade function," the company wrote. "An attacker could exploit this vulnerability by upgrading an affected device to a crafted version of firmware. A successful exploit could allow the attacker to execute arbitrary code on the affected device with full privileges." * Cisco kindly reveals proof of concept attacks for flaws in rival Netgear's kit * April Patch Tuesday: Ransomware gangs already exploiting this Windows bug * Switchzilla revisits training and cert tools with looming debut of 'Cisco U.' * Burn, backlog, burn: Cisco inferno clears away supply chain hassles DBAPPsecurity, a network security company in China, alerted Cisco to the vulnerability, according to the network box maker. Cisco's Product Security Incident Response Team (PSIRT) doesn't know of any exploitation of the vulnerability. The ATA 190 Series adapter has been available for almost a decade and, like the SPA112 adapter, enables enterprises to turn analog devices like phones, fax machines, and paging systems into IP devices. They can then be used by companies with enterprise networks, small offices, and unified communications-as-a-service cloud operations. [cso] However, the ATA 190 Series may be a relatively short-term solution. It has its own final updates scheduled for March 2024. Before migrating to the ATA 190 adapters, organizations should make sure the device will address their network needs and that their hardware and software configurations are supported by the device, Cisco wrote. While there doesn't seem to have been attacks exploiting the vulnerability in the wild, upgrading to still-supported adapters would make sense. Cisco's Talos threat intelligence unit said last month that Russian intelligence operatives, working under the APT28 threat group umbrella, in 2021 exploited an old vulnerability in Cisco routers to gather network data from US and European government agencies. Cisco had issued a fix for the flaw in 2017, though some routers remain unpatched. Talos said miscreants are only getting better and better at their attacks on networks, including exploiting known flaws in vulnerable devices. (r) Get our Tech Resources # Share Similar topics * Cisco * Firmware * Network More like these x Similar topics * Cisco * Firmware * Network * Voice over IP * Vulnerability Narrower topics * Black Hole * Broadband * Broadcom * Cellular network * Email * Ericsson * Ethernet * Firewall * IETF * IPv4 * IPv6 * Kenna Security * Network interface card * Network switch * Radio Access Network * Router * SmartNIC * Software-defined network * Streaming video * Submarine cable * Systems Approach * VPN * Webex * World Wide Web * Y2K * Zero Day Initiative Broader topics * 8x8 * Internet * IoT * Operating System * Security * Telecommunications Similar topics # Share 5 comment bubble on white COMMENTS Similar topics * Cisco * Firmware * Network More like these x Similar topics * Cisco * Firmware * Network * Voice over IP * Vulnerability Narrower topics * Black Hole * Broadband * Broadcom * Cellular network * Email * Ericsson * Ethernet * Firewall * IETF * IPv4 * IPv6 * Kenna Security * Network interface card * Network switch * Radio Access Network * Router * SmartNIC * Software-defined network * Streaming video * Submarine cable * Systems Approach * VPN * Webex * World Wide Web * Y2K * Zero Day Initiative Broader topics * 8x8 * Internet * IoT * Operating System * Security * Telecommunications TIP US OFF Send us news --------------------------------------------------------------------- Other stories you might like Beware of geeks bearing gifts, so check the fine print on Cisco's latest financing deal Buy now, even services or second-hand kit, and pay in 2024 ... if you feel lucky Networks4 May 2023 | 4 Russian snoops just love invading unpatched Cisco gear, America and UK warn Spying on foreign targets? That's our job! CSO18 Apr 2023 | 7 Mirai botnet loves exploiting your unpatched TP-Link routers, CISA warns Oracle and Apache holes also on Uncle Sam's list of big bad abused bugs Patches2 May 2023 | 1 The good, the bad and the generative AI ChatGPT is just the beginning: CISOs need to prepare for the next wave of AI-powered attacks Sponsored Feature [cso] Aruba's AI strategy cuts the backchat, talks network automation instead What's NaaS? Whatever customers need it to be Networks25 Apr 2023 | UK emergency services take DIY approach amid 12-year wait for comms upgrade Motorola's contract departure draws question mark over future of ESN Networks28 Apr 2023 | 74 Spain gets EU cash to test next gen network, and US 'scrum for 6G' already under way How much better do mobile networks really have to be by 2030-ish? Networks26 Apr 2023 | 28 China again signals desire to shape global IPv6 standards As local usage slips despite annual call to do better Networks28 Apr 2023 | 36 European companies form space jam to secure comms sovereignty with satellites IRIS2 program aims to get the EU off other countries' infrastructure Networks5 May 2023 | 3 Broadcom chases AI craze with ML-tuned switch ASICs Faster GPUs don't mean much if you've got a network bottleneck Systems20 Apr 2023 | Ericsson braces for 'choppy' year despite meeting Q1 expectations Waning 5G deployments in response to economic uncertainty blamed Networks18 Apr 2023 | Energy efficiency starts to rock telcos' 5G infrastructure choices And not only because not considering their options makes them look bad Energy Efficient Datacenters13 Apr 2023 | 10 The Register icon Biting the hand that feeds IT About Us* * Contact us * Advertise with us * Who we are Our Websites* * The Next Platform * DevClass * Blocks and Files Your Privacy* * Cookies Policy * Privacy Policy * T's & C's * Do not sell my personal information Situation Publishing Copyright. All rights reserved (c) 1998-2023 no-js