The default configuration of Cisco Small Business IP phones SPA 300 7.5.5 and SPA 500 7.5.5 does not properly support authentication, which allows remote attackers to read audio-stream data or originate telephone calls via a crafted XML request, aka Bug ID CSCuo52482.
Source: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-0670
Reference (s):
- CISCO:20150319 Cisco Small Business SPA300 and SPA500 Series IP Phones Unauthenticated Remote Dial Vulnerability
- URL: http://tools.cisco.com/security/center/viewAlert.x?alertId=37946
- SECTRACK:1031969
- URL: http://www.securitytracker.com/id/1031969