CVE-2023-20218 Details
Description
A vulnerability in web-based management interface of Cisco SPA500 Series Analog Telephone Adapters (ATAs) could allow an authenticated, remote attacker to to modify a web page in the context of a user's browser. This vulnerability is due to insufficient validation of user-supplied input by the web-based management interface of the affected software. An attacker could exploit this vulnerability by persuading a user to click a crafted link. A successful exploit could allow the attacker to alter the contents of a web page to redirect the user to potentially malicious websites, or the attacker could use this vulnerability to conduct further client-side attacks. Cisco will not release software updates that address this vulnerability. {{value}} ["%7b%7bvalue%7d%7d"])}]]
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Oct 17, 2024References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-79 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | [email protected] |
| CWE-80 | Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| cisco spa500ds firmware | All versions |
CPE
Remediation
| |
| cisco spa500ds | All versions |
CPE
Remediation
| |
| cisco spa500s firmware | All versions |
CPE
Remediation
| |
| cisco spa500s | All versions |
CPE
Remediation
| |
| cisco spa501g firmware | All versions |
CPE
Remediation
| |
| cisco spa501g | All versions |
CPE
Remediation
| |
| cisco spa502g firmware | All versions |
CPE
Remediation
| |
| cisco spa502g | All versions |
CPE
Remediation
| |
| cisco spa504g firmware | All versions |
CPE
Remediation
| |
| cisco spa504g | All versions |
CPE
Remediation
| |
| cisco spa508g firmware | All versions |
CPE
Remediation
| |
| cisco spa508g | All versions |
CPE
Remediation
| |
| cisco spa509g firmware | All versions |
CPE
Remediation
| |
| cisco spa509g | All versions |
CPE
Remediation
| |
| cisco spa512g firmware | All versions |
CPE
Remediation
| |
| cisco spa512g | All versions |
CPE
Remediation
| |
| cisco spa514g firmware | All versions |
CPE
Remediation
| |
| cisco spa514g | All versions |
CPE
Remediation
| |
| cisco spa525 firmware | All versions |
CPE
Remediation
| |
| cisco spa525 | All versions |
CPE
Remediation
| |
| cisco spa525g firmware | All versions |
CPE
Remediation
| |
| cisco spa525g | All versions |
CPE
Remediation
| |
| cisco spa525g2 firmware | All versions |
CPE
Remediation
| |
| cisco spa525g2 | All versions |
CPE
Remediation
| |
Change History
6 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Nov 21, 2024 | CVE Modified | CVE |
| May 14, 2024 | CVE Modified | [email protected] |
| Jan 25, 2024 | CVE Modified | [email protected] |
| Aug 9, 2023 | Initial Analysis | [email protected] |