Cisco Small Business SPA500 Series IP Phones Local Code Execution (CVE-2019-15959)

medium Tenable OT Security Plugin ID 505923

Synopsis

The remote OT asset is affected by a vulnerability.

Description

A vulnerability in Cisco Small Business SPA500 Series IP Phones could allow a physically proximate attacker to execute arbitrary commands on the device. The vulnerability is due to the presence of development testing and verification scripts that remained on the device. An attacker could exploit this vulnerability by accessing the physical interface of a device and inserting a USB storage device. A successful exploit could allow the attacker to execute scripts on the device in an elevated security context.

This plugin only works with Tenable.ot.
Please visit https://www.tenable.com/products/tenable-ot for more information.

Solution

Refer to the vendor advisory.

See Also

http://www.nessus.org/u?ed9258c9

Plugin Details

Severity: Medium

ID: 505923

File Name: tenable_ot_cisco_CVE-2019-15959.nasl

Version: 1.1

Type: Remote

Family: Tenable.ot

Published: 8/3/2026

Updated: 8/3/2026

Supported Sensors: Tenable OT Security

Risk Information

VPR

Risk Factor: Medium

Score: 4.9

Percentile: 57.15

CVSS v2

Risk Factor: Medium

Base Score: 4.6

Vector: CVSS2#AV:L/AC:L/Au:N/C:P/I:P/A:P

CVSS Score Source: CVE-2019-15959

CVSS v3

Risk Factor: Medium

Base Score: 6.6

Vector: CVSS:3.0/AV:P/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Vulnerability Information

CPE: cpe:/o:cisco:spa500_series_ip_phones_firmware

Required KB Items: Tenable.ot/Cisco

Patch Publication Date: 9/23/2020

Vulnerability Publication Date: 9/23/2020

Reference Information

CVE: CVE-2019-15959

CWE: 20