Home Cisco CVE-2024-20450
Back to Cisco

CVE-2024-20450

Cisco SPA300/500 Series IP Phones - Web UI

Cisco CVSS 9.8 Updated March 16, 2026

Executive Risk Summary

"Multiple vulnerabilities in the web-based management interface of Cisco Small Business SPA300 Series IP Phones and Cisco Small Business SPA500 Series IP Phones could allow an unauthenticated, remote attacker to execute arbitrary commands on the underlying operating system with root privileges. A successful exploit could allow the attacker to overflow an internal buffer and execute arbitrary commands at the root privilege level."

Operational Audit Arsenal

Target Type Firmware Image
Target Asset httpd
Standard Path Global Firmware

Manual Verification Required

This is a non-Windows asset (Cisco). Use the target asset details and official path provided above to verify your current version against the official vendor advisories listed below.

Patch Impact Forecast

Reboot Required Likely

Potential service disruption during firmware update

Internal Work Notes

CVE-2024-20450: Unauthenticated remote command execution vulnerability in Cisco SPA300/500 Series IP Phones, requiring firmware update

Technical Intelligence & Operational Utilities • Delivered Weekly

Intelligence Sources

Related Cisco Threats

Data compiled from NVD, MSRC, and CISA KEV Catalog. Intelligence synthesized via AI. Scripts provided for diagnostic purposes under MIT License.