Cisco IP Phone Remote Code Execution and Denial of Service Vulnerability
Published Feb 5, 2020
8.8
HIGHCVSS 3.1
EPSS 3.09%
Description
A vulnerability in the Cisco Discovery Protocol implementation for the Cisco IP Phone could allow an unauthenticated, adjacent attacker to remotely execute code with root privileges or cause a reload of an affected IP phone. The vulnerability is due to missing checks when processing Cisco Discovery Protocol messages. An attacker could exploit this vulnerability by sending a crafted Cisco Discovery Protocol packet to the targeted IP phone. A successful exploit could allow the attacker to remotely execute code with root privileges or cause a reload of an affected IP phone, resulting in a denial of service (DoS) condition. Cisco Discovery Protocol is a Layer 2 protocol. To exploit this vulnerability, an attacker must be in the same broadcast domain as the affected device (Layer 2 adjacent).
Affected products
-
- Version unspecifiedStatusaffectedConstraints<12.7(1)
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| Cisco | Cisco IP phone | n/a |
|
Configuration 1
- < 12.7\(1\)
- < 11.3\(1\)sr1
Running on/with
- n/a
Configuration 2
- < 12.7\(1\)
- < 11.3\(1\)sr1
Running on/with
- n/a
Configuration 3
- < 11.3\(1\)sr1
Running on/with
- n/a
Configuration 4
- < 11.3\(1\)sr1
Running on/with
- n/a
Configuration 5
- < 11.3\(1\)sr1
Running on/with
- n/a
Configuration 6
- < 11.3\(1\)sr1
Running on/with
- n/a
Configuration 7
- < 11.3\(1\)sr1
Running on/with
- n/a
Configuration 8
- < 12.7\(1\)
- < 11.3\(1\)sr1
Running on/with
- n/a
Configuration 9
- < 12.7\(1\)
- < 11.3\(1\)sr1
Running on/with
- n/a
Configuration 10
- < 12.7\(1\)
- < 11.3\(1\)sr1
Running on/with
- n/a
Configuration 11
- < 12.7\(1\)
- < 11.3\(1\)sr1
Running on/with
- n/a
Configuration 12
- < 12.7\(1\)
- < 11.3\(1\)sr1
Running on/with
- n/a
Configuration 13
- < 12.7\(1\)
- < 11.3\(1\)sr1
Running on/with
- n/a
Configuration 14
- < 12.7\(1\)
- < 11.3\(1\)sr1
Running on/with
- n/a
Configuration 15
- < 12.7\(1\)
- < 11.3\(1\)sr1
Running on/with
- n/a
Configuration 16
- < 12.7\(1\)
- < 11.3\(1\)sr1
Running on/with
- n/a
Configuration 17
- < 12.7\(1\)
- < 11.3\(1\)sr1
Running on/with
- n/a
Configuration 18
- < 10.3\(1\)sr6
Running on/with
- n/a
Configuration 19
Running on/with
Configuration 20
- < 11.0\(5\)sr2
Running on/with
- n/a
Configuration 21
- < 11.0\(5\)sr2
Running on/with
- n/a
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (2)
- http://packetstormsecurity.com/files/156203/Cisco-Discovery-Protocol-CDP-Remote-Device-Takeover.html x_refsource_MISCThird Party AdvisoryVDB Entry
- https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20200205-voip-phones-rce-dos vendor-advisoryx_refsource_CISCOVendor Advisory
| Link | Providers | Tags |
|---|---|---|
| http://packetstormsecurity.com/files/156203/Cisco-Discovery-Protocol-CDP-Remote-Device-Takeover.html | x_refsource_MISCThird Party AdvisoryVDB Entry | |
| https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20200205-voip-phones-rce-dos | vendor-advisoryx_refsource_CISCOVendor Advisory |
Change history (0)
No recorded changes yet.