Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Cisco’s October 2024 advisory covers eight vulnerabilities in specific Cisco ATA 191 and ATA 192 firmware tracks. The first fixed releases are ATA 191 on-premises 12.0.2 and ATA 191/192 Multiplatform 11.2.5. Administrators should identify the device’s model and firmware variant, then install the appropriate fixed release or a suitable later release confirmed in Cisco’s support documentation.

Which Cisco ATA models and firmware are affected?

Cisco’s advisory applies to vulnerable releases of ATA 191 running on-premises or Multiplatform firmware, and ATA 192 running Multiplatform firmware. It does not establish that every ATA 190 Series model is affected. The two firmware tracks have different version numbers and fixes, so confirm the exact model, firmware variant, and installed version before choosing an update. Cisco’s advisory lists these affected and fixed releases:

Firmware variant Vulnerable releases listed First fixed release
ATA 191 on-premises 12.0.1 and earlier 12.0.2
ATA 191 and ATA 192 Multiplatform 11.2.4 and earlier 11.2.5

These are the first fixed releases named in the October 2024 advisory, not necessarily the best release to install today. Cisco’s support page lists later documentation, including ATA 191 release 12.0(4), published September 10, 2026, and ATA 191/192 Multiplatform 11.3(2)SR1, published July 9, 2026. Check the current release notes for your exact firmware variant and deployment before upgrading; the existence of a later release alone does not establish that it is the currently recommended security release. Cisco ATA 190 Series support page

What can the vulnerabilities allow?

The advisory describes eight distinct CVEs that do not depend on one another. Their attack requirements and affected firmware vary, so the listed impacts should not be read as applying identically to every device or vulnerability.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
#1 Best Overall
Cisco ATA 191 Multiplatform Analog Telephone Adapter, 2-Port Handset-to-Ethernet Adapter, 1-Year Limited Hardware Warranty (ATA191-3PW-K9)
  • VERSATILE: IP phone adapter brings traditional analog devices into the IP world
  • AUDIO: Clear, natural-sounding voice quality via advanced preprocessing, high-performance echo cancellation, voice activity detection, and comfort noise generation
  • SECURITY: Supports the latest encryption with Transport Layer Security (TLS), Secure Hash Algorithm (SHA-2) and new Secure Real-time Protocol (sRTP) cipher suites
  • HARDWARE: Two RJ-11 FXS ports and one 10/100 Mbps RJ-45 Ethernet port
  • PEACE OF MIND: 1-year limited hardware warranty

Unauthenticated access to management endpoints

The highest-scored issue, CVE-2024-20458, has a CVSS base score of 8.2 assigned by Cisco. An unauthenticated remote attacker could reach specific HTTP endpoints in the web-based management interface and view or delete configuration or change firmware.

Cross-site request forgery and other impacts

CVE-2024-20421 is rated 7.1 by Cisco and involves cross-site request forgery: if a targeted user follows a crafted link, an attacker could cause actions to be performed with that user’s privileges. The remaining issues have Cisco CVSS base scores of 6.5, 6.1, 6.0, 5.5, 5.4, and 5.4. Across the eight vulnerabilities, the advisory also describes possible reflected cross-site scripting after a user follows a crafted link; remote or local command execution as root by a high-privilege authenticated user; disclosure of other users’ passwords to a low-privilege local attacker; configuration changes or a device reboot; and escalation from a low-privilege account to Admin commands. Each impact depends on the applicable CVE’s prerequisites and firmware track. Cisco’s advisory

Rank #2
Sale
Cisco ATA 191 Multiplatform 2-Port Analog Telephone Adapter (ATA191-3PW-K9) (Renewed)
  • VERSATILE: IP phone adapter brings traditional analog devices into the IP world
  • AUDIO: Clear, natural-sounding voice quality via advanced preprocessing, high-performance echo cancellation, voice activity detection, and comfort noise generation
  • SECURITY: Supports the latest encryption with Transport Layer Security (TLS), Secure Hash Algorithm (SHA-2) and new Secure Real-time Protocol (sRTP) cipher suites
  • HARDWARE: Two RJ-11 FXS ports and one 10/100 Mbps RJ-45 Ethernet port
  • PEACE OF MIND: 1-year limited hardware warranty

How should administrators remediate the issue?

Cisco says firmware updates address the vulnerabilities and labels the security updates free. The fix is the appropriate firmware update—not replacing the adapter solely because of this advisory.

  1. Identify the device and firmware track. Confirm whether the adapter is an ATA 191 or ATA 192, whether it uses on-premises or Multiplatform firmware, and which release is installed.
  2. Select an appropriate fixed release. At minimum, the advisory’s first fixed releases are ATA 191 on-premises 12.0.2 and ATA 191/192 Multiplatform 11.2.5. Check Cisco’s current support page and the release notes for the exact variant before selecting a later version.
  3. Check readiness before upgrading. Cisco advises checking device memory and confirming that the current hardware and software configurations remain supported by the target release. If compatibility is unclear, consult Cisco TAC or the contracted maintenance provider.
  4. Use the applicable update route. Customers whose service contracts include regular software updates should use their usual update channel. If you bought directly from Cisco without a qualifying contract, or cannot obtain a fixed version through your seller, Cisco says to contact TAC with the product serial number and the advisory URL. A free security update does not grant a new software license, different feature set, or major revision upgrade.

The Multiplatform 11.2(5) release notes describe downloading the release, placing its files on a TFTP, HTTP, or HTTPS directory, configuring the upgrade rule, and note that the adapter reboots after upgrading. Those steps are specific to that release’s guidance; do not assume they apply unchanged to on-premises firmware or a later release. Cisco ATA 191 and 192 Multiplatform 11.2(5) release notes

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Rank #3
5V Adapter for Cisco ATA 191 192 ATA191-K9 ATA191-3PW-K9 ATA192-3PW-K9
  • [Power Specification]: Input Voltage: 100~240V Input Frequency: 50~60HZ output Voltage: 5V 2.4A
  • [Compatible with]: Cisco ATA191 TA191-K9 ATA191-PWR ATA191-3PW-K9/ Cisco ATA192 ATA192-3PW-K9
  • [Fast and Efficient Charging]: This charger delivers a rapid and efficient charge to your devices, ensuring minimal downtime. Whether you're working on an important project, streaming your favorite content, or simply browsing the web, this charger that sold by PowerHOOD provides a reliable power source to keep you going
  • [Built-in Safety Features]: Your safety is our top priority. The Charger by PowerHOOD is equipped with multiple built-in safety features, including overvoltage protection, short circuit protection, and overcurrent protection. These features ensure a stable and secure charging experience, giving you peace of mind while your devices power up
  • [Energy Efficient and Environmentally Friendly]: Not only does the Charger by PowerHOOD deliver impressive performance, but it is also energy efficient. It meets the highest energy efficiency standards, helping you reduce your carbon footprint without compromising on functionality or charging speed. Make a positive impact on the environment while enjoying the benefits of reliable power

Is there a workaround?

Cisco says there is no workaround that addresses the vulnerabilities. For CVE-2024-20458, CVE-2024-20421, CVE-2024-20459, CVE-2024-20460, CVE-2024-20463, and CVE-2024-20420, Cisco describes a limited mitigation for ATA 191 on-premises firmware only: disable the web-based management interface, which Cisco says is disabled by default.

Cisco reports that this mitigation was proven in a test environment, but administrators must evaluate whether it suits their own environment and what effect it could have on functionality or network performance. It is not a general mitigation for ATA 191 Multiplatform or ATA 192, and it does not replace applying the firmware fix.

Rank #4
CJP-Geek 5V AC DC Adapter Compatible with Cisco ATA 191 192 ATA191-K9 ATA191K9 ATA191-3PW-K9 V03 ATA192-3PW-K9 ATA1923PW-K9 2-Port Analog Telephone Adapter Power Supply Cord Cable Charger Mains PSU
  • Input Voltage: 100-240V AC,Rated Input Frequency:50/99HZ
  • Comfortable Use: Let you in the living room, bedroom, office, indoor, outdoor, can easily connect to the power socket, wall socket.
  • Excellent Material: Sturdy flame-retardant exterior shell, Protects against scratches, bumps, drops, withstands pressure and keeps internal components safe during emergencies enhanced longevity.
  • Built-in protection:Wall charge power supply include Over Voltage Protection,Over Current Protection,Short Circuit Protection,Input Protection,all-round guarantee of safe and normal use of power supply.
  • Wide compatibility:5V AC DC Adapter Compatible with Cisco ATA 191 192 ATA191-K9 ATA191K9 ATA191-3PW-K9 V03 ATA192-3PW-K9 ATA1923PW-K9 2-Port Analog Telephone Adapter Power Supply Cord Cable Charger Mains PSU
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

What does Cisco say about exploitation?

In the advisory updated October 24, 2024, Cisco credited Zack Sanchez of its Advanced Security Initiatives Group with finding the vulnerabilities during internal security testing. Cisco PSIRT said at that time that it was not aware of public announcements or malicious use. That is Cisco’s point-in-time assessment in 2024; it does not establish whether exploitation has occurred since then.

Quick Recap

Bestseller No. 1
Cisco ATA 191 Multiplatform Analog Telephone Adapter, 2-Port Handset-to-Ethernet Adapter, 1-Year Limited Hardware Warranty (ATA191-3PW-K9)
Cisco ATA 191 Multiplatform Analog Telephone Adapter, 2-Port Handset-to-Ethernet Adapter, 1-Year Limited Hardware Warranty (ATA191-3PW-K9)
VERSATILE: IP phone adapter brings traditional analog devices into the IP world; HARDWARE: Two RJ-11 FXS ports and one 10/100 Mbps RJ-45 Ethernet port
$146.17
SaleBestseller No. 2
Cisco ATA 191 Multiplatform 2-Port Analog Telephone Adapter (ATA191-3PW-K9) (Renewed)
Cisco ATA 191 Multiplatform 2-Port Analog Telephone Adapter (ATA191-3PW-K9) (Renewed)
VERSATILE: IP phone adapter brings traditional analog devices into the IP world; HARDWARE: Two RJ-11 FXS ports and one 10/100 Mbps RJ-45 Ethernet port
$105.00
Bestseller No. 5
Cisco ATA 191 Analog Telephone Adapter, ATA191-PWR
Cisco ATA 191 Analog Telephone Adapter, ATA191-PWR
eases deployment via a cisco unified communications manager central interface; provides a complete security solution for both media and signaling
$28.11
Best Value
Cisco ATA 191 Analog Telephone Adapter, ATA191-PWR
  • offers clear, natural-sounding voice quality via advanced preprocessing, high-performance echo cancellation, voice activity detection (vad), and comfort noise generation (cng)
  • eases deployment via a cisco unified communications manager central interface
  • provides a complete security solution for both media and signaling
  • Connector type: Component

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.