PT-2020-1613 · Cisco · Cisco Ip Phone

Ben Seri

·

Published

2020-02-05

·

Updated

2020-02-07

·

CVE-2020-3111

CVSS v3.1

8.8

High

VectorAV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Cisco IP Phone (affected versions not specified)
Description The issue is due to insufficient input validation in the Cisco Discovery Protocol implementation, allowing an unauthenticated, adjacent attacker to execute arbitrary code with root privileges or cause a reload of the affected IP phone. This can be achieved by sending a crafted Cisco Discovery Protocol packet to the targeted device. The vulnerability exploits missing checks when processing Cisco Discovery Protocol messages, potentially resulting in a denial of service (DoS) condition. The attacker must be in the same broadcast domain as the affected device to exploit this vulnerability.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2020-00791
CVE-2020-3111

Affected Products

Cisco Ip Phone