PT-2020-1613 · Cisco · Cisco Ip Phone
Ben Seri
·
Published
2020-02-05
·
Updated
2020-02-07
·
CVE-2020-3111
CVSS v3.1
8.8
High
| Vector | AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Cisco IP Phone (affected versions not specified)
Description
The issue is due to insufficient input validation in the Cisco Discovery Protocol implementation, allowing an unauthenticated, adjacent attacker to execute arbitrary code with root privileges or cause a reload of the affected IP phone. This can be achieved by sending a crafted Cisco Discovery Protocol packet to the targeted device. The vulnerability exploits missing checks when processing Cisco Discovery Protocol messages, potentially resulting in a denial of service (DoS) condition. The attacker must be in the same broadcast domain as the affected device to exploit this vulnerability.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Cisco Ip Phone