CVE-2024-20463 (CNNVD-202410-1715)
中文标题:
Cisco ATA 190 安全漏洞
英文标题:
Cisco ATA 190 Series Analog Telephone Adapter Firmware Command Injection and Denial of Service Vulnerability
漏洞描述
中文描述:
Cisco ATA 190是美国思科(Cisco)公司的一个模拟电话适配器。 Cisco ATA 190存在安全漏洞,该漏洞源于 HTTP 服务器允许 GET 请求中的状态更改。未经身份验证的远程攻击者利用该漏洞可以修改配置或重新启动受影响的设备。
英文描述:
A vulnerability in the web-based management interface of Cisco ATA 190 Series Analog Telephone Adapter firmware could allow an unauthenticated, remote attacker to modify the configuration or reboot an affected device. This vulnerability is due to the HTTP server allowing state changes in GET requests. An attacker could exploit this vulnerability by sending a malicious request to the web-based management interface on an affected device. A successful exploit could allow the attacker to make limited modifications to the configuration or reboot the device, resulting in a denial of service (DoS) condition.
CWE类型:
标签:
受影响产品
| 厂商 | 产品 | 版本 | 版本范围 | 平台 | CPE |
|---|---|---|---|---|---|
| Cisco | Cisco Analog Telephone Adaptor (ATA) Software | 12.0.1 SR2 | - | - |
cpe:2.3:a:cisco:cisco_analog_telephone_adaptor_(ata)_software:12.0.1_sr2:*:*:*:*:*:*:*
|
| Cisco | Cisco Analog Telephone Adaptor (ATA) Software | 11.1.0 | - | - |
cpe:2.3:a:cisco:cisco_analog_telephone_adaptor_(ata)_software:11.1.0:*:*:*:*:*:*:*
|
| Cisco | Cisco Analog Telephone Adaptor (ATA) Software | 12.0.1 SR1 | - | - |
cpe:2.3:a:cisco:cisco_analog_telephone_adaptor_(ata)_software:12.0.1_sr1:*:*:*:*:*:*:*
|
| Cisco | Cisco Analog Telephone Adaptor (ATA) Software | 11.1.0 MSR1 | - | - |
cpe:2.3:a:cisco:cisco_analog_telephone_adaptor_(ata)_software:11.1.0_msr1:*:*:*:*:*:*:*
|
| Cisco | Cisco Analog Telephone Adaptor (ATA) Software | 12.0.1 | - | - |
cpe:2.3:a:cisco:cisco_analog_telephone_adaptor_(ata)_software:12.0.1:*:*:*:*:*:*:*
|
| Cisco | Cisco Analog Telephone Adaptor (ATA) Software | 11.1.0 MSR2 | - | - |
cpe:2.3:a:cisco:cisco_analog_telephone_adaptor_(ata)_software:11.1.0_msr2:*:*:*:*:*:*:*
|
| Cisco | Cisco Analog Telephone Adaptor (ATA) Software | 11.1.0 MSR3 | - | - |
cpe:2.3:a:cisco:cisco_analog_telephone_adaptor_(ata)_software:11.1.0_msr3:*:*:*:*:*:*:*
|
| Cisco | Cisco Analog Telephone Adaptor (ATA) Software | 11.1.0 MSR4 | - | - |
cpe:2.3:a:cisco:cisco_analog_telephone_adaptor_(ata)_software:11.1.0_msr4:*:*:*:*:*:*:*
|
| Cisco | Cisco Analog Telephone Adaptor (ATA) Software | 12.0.1 SR3 | - | - |
cpe:2.3:a:cisco:cisco_analog_telephone_adaptor_(ata)_software:12.0.1_sr3:*:*:*:*:*:*:*
|
| Cisco | Cisco Analog Telephone Adaptor (ATA) Software | 11.2.1 | - | - |
cpe:2.3:a:cisco:cisco_analog_telephone_adaptor_(ata)_software:11.2.1:*:*:*:*:*:*:*
|
| Cisco | Cisco Analog Telephone Adaptor (ATA) Software | 12.0.1 SR4 | - | - |
cpe:2.3:a:cisco:cisco_analog_telephone_adaptor_(ata)_software:12.0.1_sr4:*:*:*:*:*:*:*
|
| Cisco | Cisco Analog Telephone Adaptor (ATA) Software | 11.2.2 | - | - |
cpe:2.3:a:cisco:cisco_analog_telephone_adaptor_(ata)_software:11.2.2:*:*:*:*:*:*:*
|
| Cisco | Cisco Analog Telephone Adaptor (ATA) Software | 11.2.2 MSR1 | - | - |
cpe:2.3:a:cisco:cisco_analog_telephone_adaptor_(ata)_software:11.2.2_msr1:*:*:*:*:*:*:*
|
| Cisco | Cisco Analog Telephone Adaptor (ATA) Software | 12.0.1 SR5 | - | - |
cpe:2.3:a:cisco:cisco_analog_telephone_adaptor_(ata)_software:12.0.1_sr5:*:*:*:*:*:*:*
|
| Cisco | Cisco Analog Telephone Adaptor (ATA) Software | 11.2.3 | - | - |
cpe:2.3:a:cisco:cisco_analog_telephone_adaptor_(ata)_software:11.2.3:*:*:*:*:*:*:*
|
| Cisco | Cisco Analog Telephone Adaptor (ATA) Software | 11.2.4 | - | - |
cpe:2.3:a:cisco:cisco_analog_telephone_adaptor_(ata)_software:11.2.4:*:*:*:*:*:*:*
|
| cisco | ata_191_firmware | * | - | - |
cpe:2.3:o:cisco:ata_191_firmware:*:*:*:*:*:*:*:*
|
| cisco | ata_192_firmware | * | - | - |
cpe:2.3:o:cisco:ata_192_firmware:*:*:*:*:*:*:*:*
|
解决方案
中文解决方案:
英文解决方案:
临时解决方案:
参考链接
cve.org
CVSS评分详情
3.1 (cna)
MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L
时间信息
利用信息
数据源详情
| 数据源 | 记录ID | 版本 | 提取时间 |
|---|---|---|---|
| CVE | cve_CVE-2024-20463 |
2025-11-11 15:22:24 | 2025-11-11 07:39:03 |
| NVD | nvd_CVE-2024-20463 |
2025-11-11 15:00:07 | 2025-11-11 07:47:05 |
| CNNVD | cnnvd_CNNVD-202410-1715 |
2025-11-11 15:12:18 | 2025-11-11 07:59:10 |
版本与语言
安全公告
变更历史
查看详细变更
- vulnerability_type: 未提取 -> 其他
- cnnvd_id: 未提取 -> CNNVD-202410-1715
- data_sources: ['cve', 'nvd'] -> ['cnnvd', 'cve', 'nvd']
查看详细变更
- affected_products_count: 16 -> 18
- data_sources: ['cve'] -> ['cve', 'nvd']