Dump these insecure phone adapters because we're not fixing them, says Cisco

© Provided by The Register Security hole ranks 9.8 out of 10 in severity, 0 out of 10 in patch availability

There is a critical security flaw in a Cisco phone adapter, and the business technology giant says the only step to take is dumping the hardware and migrating to new kit.…

In an advisory, Cisco this week warned about the vulnerability in the SPA112 2-Port Adapter that, if exploited, could allow a remote attacker to essentially take control of a compromised device by seizing full privileges and executing arbitrary code.

The flaw, tracked as CVE-2023-20126, is rated as "critical," with a base score of 9.8 out of 10.

CONSTELLATION BRANDS, INC.

Adding to the problem is the fact that the adapter reached its end of life in June 2020, and while the last date to extend or renew a service contract for the product isn't until August 2024, Cisco said in the advisory it will not release firmware updates to address the flaw and there are no workarounds.

"Customers are encouraged to migrate to a Cisco ATA 190 Series Analog Telephone Adapter," the manufacturer wrote in its advisory.

The Register has asked Cisco for more information, and will update the story if a response comes in.

The flaw is in the web-based management interface for the two-port adapter, which is used by organizations to connect analog phones and fax machines (please don't ask us to explain what those are) to voice-over-IP systems without having to upgrade them.

The vulnerability stems from a missing authentication process in the firmware upgrade function, according to Cisco.

"This vulnerability is due to a missing authentication process within the firmware upgrade function," the company wrote. "An attacker could exploit this vulnerability by upgrading an affected device to a crafted version of firmware. A successful exploit could allow the attacker to execute arbitrary code on the affected device with full privileges."

DBAPPsecurity, a network security company in China, alerted Cisco to the vulnerability, according to the network box maker. Cisco's Product Security Incident Response Team (PSIRT) doesn't know of any exploitation of the vulnerability.

The ATA 190 Series adapter has been available for almost a decade and, like the SPA112 adapter, enables enterprises to turn analog devices like phones, fax machines, and paging systems into IP devices. They can then be used by companies with enterprise networks, small offices, and unified communications-as-a-service cloud operations.

We note that the 190 specifically has its own final updates scheduled for March 2024; Cisco recommends people use the ATA 191 and later models.

Before migrating to whichever new adapter, organizations should make sure the device will address their network needs and that their hardware and software configurations are supported by the device, Cisco wrote.

While there doesn't seem to have been attacks exploiting the vulnerability in the wild, upgrading to still-supported adapters would make sense. Cisco's Talos threat intelligence unit said last month that Russian intelligence operatives, working under the APT28 threat group umbrella, in 2021 exploited an old vulnerability in Cisco routers to gather network data from US and European government agencies.

Cisco had issued a fix for the flaw in 2017, though some routers remain unpatched. Talos said miscreants are only getting better and better at their attacks on networks, including exploiting known flaws in vulnerable devices. ®


 


Unquestionably it is hard assignment to pick dependable certification questions/answers assets regarding review, reputation and validity since individuals get sham because of picking incorrectly benefit. Killexams.com ensure to serve its customers best to its assets concerning exam dumps update and validity. The vast majority of other's sham report dissension customers come to us for the brain dumps and pass their exams joyfully and effortlessly. We never trade off on our review, reputation and quality on the grounds that killexams review, killexams reputation and killexams customer certainty is imperative to us. Uniquely we deal with killexams.com review, killexams.com reputation, killexams.com sham report objection, killexams.com trust, killexams.com validity, killexams.com report and killexams.com scam. On the off chance that you see any false report posted by our rivals with the name killexams sham report grievance web, killexams.com sham report, killexams.com scam, killexams.com protest or something like this, simply remember there are constantly awful individuals harming reputation of good administrations because of their advantages. There are a huge number of fulfilled clients that pass their exams utilizing killexams.com brain dumps, killexams PDF questions, killexams hone questions, killexams exam simulator. Visit Killexams.com, our specimen questions and test brain dumps, our exam simulator and you will realize that killexams.com is the best brain dumps site.

Which is the best dumps website?
Certainly, Killexams is totally legit along with fully trusted. There are several functions that makes killexams.com unique and legitimate. It provides updated and totally valid exam dumps formulated with real exams questions and answers. Price is extremely low as compared to the vast majority of services on internet. The questions and answers are up graded on ordinary basis with most recent brain dumps. Killexams account setup and supplement delivery is really fast. Report downloading will be unlimited and very fast. Help is avaiable via Livechat and Message. These are the characteristics that makes killexams.com a robust website that provide exam dumps with real exams questions.



Is killexams.com test material dependable?
There are several Questions and Answers provider in the market claiming that they provide Actual Exam Questions, Braindumps, Practice Tests, Study Guides, cheat sheet and many other names, but most of them are re-sellers that do not update their contents frequently. Killexams.com is best website of Year 2023 that understands the issue candidates face when they spend their time studying obsolete contents taken from free pdf download sites or reseller sites. Thats why killexams.com update Exam Questions and Answers with the same frequency as they are updated in Real Test. Exam dumps provided by killexams.com are Reliable, Up-to-date and validated by Certified Professionals. They maintain Question Bank of valid Questions that is kept up-to-date by checking update on daily basis.

If you want to Pass your Exam Fast with improvement in your knowledge about latest course contents and topics of new syllabus, We recommend to Download PDF Exam Questions from killexams.com and get ready for actual exam. When you feel that you should register for Premium Version, Just choose visit killexams.com and register, you will receive your Username/Password in your Email within 5 to 10 minutes. All the future updates and changes in Questions and Answers will be provided in your Download Account. You can download Premium Exam Dumps files as many times as you want, There is no limit.

Killexams.com has provided VCE Practice Test Software to Practice your Exam by Taking Test Frequently. It asks the Real Exam Questions and Marks Your Progress. You can take test as many times as you want. There is no limit. It will make your test prep very fast and effective. When you start getting 100% Marks with complete Pool of Questions, you will be ready to take Actual Test. Go register for Test in Test Center and Enjoy your Success.




CRT-271 past exams | C1000-024 cbt | PL-300 cram | Platform-App-Builder practice exam | 1T6-323 exam answers | 199-01 Free PDF | T1-GR1 Questions and Answers | NS0-184 test prep | H12-111_V2.5-ENU Exam Braindumps | ATA bootcamp | 200-901 practice exam | WCNA practice questions | CBBF free pdf | 200-201 free online test | PEGAPCSSA87V1 free prep | KCNA exam prep | 201-450 Practice test | 830-01 real questions | CPM mock exam | BCP-520 writing test questions |


200-901 - DevNet Associate (DEVASC) Questions and Answers
200-901 - DevNet Associate (DEVASC) exam dumps
200-901 - DevNet Associate (DEVASC) education
200-901 - DevNet Associate (DEVASC) Actual Questions
200-901 - DevNet Associate (DEVASC) PDF Questions
200-901 - DevNet Associate (DEVASC) study help
200-901 - DevNet Associate (DEVASC) exam dumps
200-901 - DevNet Associate (DEVASC) testing
200-901 - DevNet Associate (DEVASC) PDF Download
200-901 - DevNet Associate (DEVASC) book
200-901 - DevNet Associate (DEVASC) Real Exam Questions
200-901 - DevNet Associate (DEVASC) exam success
200-901 - DevNet Associate (DEVASC) education
200-901 - DevNet Associate (DEVASC) test
200-901 - DevNet Associate (DEVASC) Real Exam Questions
200-901 - DevNet Associate (DEVASC) Exam Questions
200-901 - DevNet Associate (DEVASC) guide
200-901 - DevNet Associate (DEVASC) Exam Braindumps
200-901 - DevNet Associate (DEVASC) PDF Download
200-901 - DevNet Associate (DEVASC) study help
200-901 - DevNet Associate (DEVASC) outline
200-901 - DevNet Associate (DEVASC) information search
200-901 - DevNet Associate (DEVASC) book
200-901 - DevNet Associate (DEVASC) Exam dumps
200-901 - DevNet Associate (DEVASC) guide
200-901 - DevNet Associate (DEVASC) exam contents
200-901 - DevNet Associate (DEVASC) Questions and Answers
200-901 - DevNet Associate (DEVASC) exam contents
200-901 - DevNet Associate (DEVASC) PDF Download
200-901 - DevNet Associate (DEVASC) PDF Download
200-901 - DevNet Associate (DEVASC) boot camp
200-901 - DevNet Associate (DEVASC) boot camp
200-901 - DevNet Associate (DEVASC) tricks
200-901 - DevNet Associate (DEVASC) Practice Questions
200-901 - DevNet Associate (DEVASC) teaching
200-901 - DevNet Associate (DEVASC) education
200-901 - DevNet Associate (DEVASC) guide
200-901 - DevNet Associate (DEVASC) Actual Questions

Other Cisco Exam Dumps


300-730 practice exam | 300-420 Latest Questions | 500-470 free pdf | 350-601 test exam | 200-201 dumps questions | 500-490 practice test | 300-620 braindumps | 010-151 dumps | 300-515 prep questions | 500-275 free prep | 300-815 test sample | 300-415 Exam dumps | 300-435 Exam Questions | 300-635 study guide | 500-440 online exam | 700-020 sample questions | 100-490 Exam Braindumps | 300-410 cram | 300-510 sample test questions | 500-052 test prep |


Best Exam Dumps You Ever Experienced


P11-101 PDF Dumps | BCP-521 test exam | CPIM PDF Questions | IIA-CIA-Part2 Exam Questions | AngularJS exam questions | UIPATH-RPAV1 mock exam | LE0-583 practice questions | PANRE bootcamp | CPCM past exams | GMAT-Verbal test prep | Adwords-Reporting questions download | PSP exam questions | DSST-HRM Dumps | CFP free pdf | 3171T test practice | 050-ENVCSE01 test prep | CISMP-V9 Exam Cram | CPIM-MPR real questions | OCN training material | NCP-MCI practice exam |





References :


https://sites.google.com/view/killexams-200-901-pdf-dumps
https://killexamsprectictest.blogspot.com/2021/01/200-901-devnet-associate-devasc-dumps.html
https://drp.mk/i/Fnhm6W6PzV
https://www.instapaper.com/read/1400150119
http://feeds.feedburner.com/FreeKillexamscomBcp-221QuestionBank
https://files.fm/f/5mg6zk5s7



Similar Websites :
Pass4sure Certification Exam dumps
Pass4Sure Exam Questions and Dumps




Back to Main Page