CVE-2019-15959
A vulnerability in Cisco Small Business SPA500 Series IP Phones could allow a physically proximate attacker to execute arbitrary commands on the device. The vulnerability is due to the presence of development testing and verification scripts that remained on the device. An attacker could exploit this vulnerability by accessing the physical interface of a device and inserting a USB storage device. A successful exploit could allow the attacker to execute scripts on the device in an elevated security context.
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:P/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- Puntuación base: 6.6
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.39%
- Percentil entre todas las CVEs puntuadas: 31
- Fecha de la puntuación: 7/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
🎯 Técnicas ATT&CK
Cómo se explota esta vulnerabilidad y qué consigue el atacante, en el lenguaje de MITRE ATT&CK.
- Explotación
T1091Replication Through Removable Medialateral movement · initial access - Impacto principal
T1059Command and Scripting Interpreterexecution
Fuente: mapeo oficial MITRE CTID (CVE → ATT&CK).
🛡️ Mitigaciones ATT&CK que cubren estas técnicas
Tecnologías afectadas (1)
CWE
- CWE-20
- CWE-20
Referencias
JSON original (NVD)
Mostrar
{
"id": "CVE-2019-15959",
"cveTags": [],
"metrics": {
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2019-15959",
"role": "CISA Coordinator",
"options": [
{
"exploitation": "none"
},
{
"automatable": "no"
},
{
"technicalImpact": "total"
}
],
"version": "2.0.3",
"timestamp": "2024-11-13T17:18:00.455449Z"
}
}
],
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 4.6,
"accessVector": "LOCAL",
"vectorString": "AV:L/AC:L/Au:N/C:P/I:P/A:P",
"authentication": "NONE",
"integrityImpact": "PARTIAL",
"accessComplexity": "LOW",
"availabilityImpact": "PARTIAL",
"confidentialityImpact": "PARTIAL"
},
"acInsufInfo": false,
"impactScore": 6.4,
"baseSeverity": "MEDIUM",
"obtainAllPrivilege": false,
"exploitabilityScore": 3.9,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
],
"cvssMetricV30": [
{
"type": "Secondary",
"source": "psirt@cisco.com",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.0",
"baseScore": 6.6,
"attackVector": "PHYSICAL",
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.0/AV:P/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"integrityImpact": "HIGH",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "HIGH",
"privilegesRequired": "LOW",
"confidentialityImpact": "HIGH"
},
"impactScore": 5.9,
"exploitabilityScore": 0.7
}
],
"cvssMetricV31": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 6.6,
"attackVector": "PHYSICAL",
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:P/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"integrityImpact": "HIGH",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "HIGH",
"privilegesRequired": "LOW",
"confidentialityImpact": "HIGH"
},
"impactScore": 5.9,
"exploitabilityScore": 0.7
}
]
},
"affected": [
{
"source": "psirt@cisco.com",
"affectedData": [
{
"vendor": "Cisco",
"product": "Cisco SPA525G2 5-line IP Phone",
"versions": [
{
"status": "affected",
"version": "n/a"
}
]
}
]
}
],
"published": "2020-09-23T01:15:12.863",
"references": [
{
"url": "https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20191106-spa500-script",
"tags": [
"Vendor Advisory"
],
"source": "psirt@cisco.com"
},
{
"url": "https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20191106-spa500-script",
"tags": [
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Secondary",
"source": "psirt@cisco.com",
"description": [
{
"lang": "en",
"value": "CWE-20"
}
]
},
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "CWE-20"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "A vulnerability in Cisco Small Business SPA500 Series IP Phones could allow a physically proximate attacker to execute arbitrary commands on the device. The vulnerability is due to the presence of development testing and verification scripts that remained on the device. An attacker could exploit this vulnerability by accessing the physical interface of a device and inserting a USB storage device. A successful exploit could allow the attacker to execute scripts on the device in an elevated security context."
},
{
"lang": "es",
"value": "Una vulnerabilidad en Cisco Small Business SPA500 Series IP Phones, podría permitir a un atacante cercano físicamente ejecutar comandos arbitrarios en el dispositivo. La vulnerabilidad es debido a la presencia de una prueba de desarrollo y una verificación de scripts que permanecieron en el dispositivo. Un atacante podría explotar esta vulnerabilidad mediante el acceso a la interfaz física de un dispositivo e insertando un dispositivo de almacenamiento USB. Una explotación con éxito podría permitir al atacante ejecutar scripts en el dispositivo en un contexto de seguridad elevado"
}
],
"lastModified": "2026-06-17T02:21:25.427",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:cisco:spa500_series_ip_phones_firmware:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "B676D2B9-4046-450A-BFD5-000CBAE26955",
"versionEndIncluding": "7.5.7\\(5\\)"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:cisco:spa500ds:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "9C7B9304-CCA9-41C0-A6B9-032DC923420C"
},
{
"criteria": "cpe:2.3:h:cisco:spa500s:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "66B2A148-467A-4F10-945C-1F49A218BD4F"
},
{
"criteria": "cpe:2.3:h:cisco:spa501g:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "73B67905-79ED-4771-B436-49868BA7C922"
},
{
"criteria": "cpe:2.3:h:cisco:spa502g:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "D371387F-C7CC-46BB-85E9-419EF97D2A00"
},
{
"criteria": "cpe:2.3:h:cisco:spa504g:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "D3FE12AB-1CC7-450D-88F2-7B06C51DCE7C"
},
{
"criteria": "cpe:2.3:h:cisco:spa512g:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "92A92FEE-7CB5-43B1-8AC3-00C077DD4A63"
},
{
"criteria": "cpe:2.3:h:cisco:spa514g:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "16C4089F-5B9F-4D69-8819-43B52309454F"
},
{
"criteria": "cpe:2.3:h:cisco:spa525g:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "B5602EAB-6507-4B5B-A05B-4FED970B43D0"
},
{
"criteria": "cpe:2.3:h:cisco:spa525g2:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "58E0A339-CE89-4D27-B08D-BF151C9FF086"
}
],
"operator": "OR"
}
],
"operator": "AND"
}
],
"sourceIdentifier": "psirt@cisco.com"
}