A vulnerability in the Cisco Discovery Protocol functionality of Cisco ATA 190 Series Adaptive Telephone Adapter firmware could allow an unauthenticated, remote attacker to cause a DoS condition on an affected device. This vulnerability is due to an out-of-bounds read when processing Cisco Discovery Protocol packets. An attacker could exploit this vulnerability by sending crafted Cisco Discovery Protocol packets to an affected device. A successful exploit could allow the attacker to cause a service restart.Cisco has released firmware updates that address this vulnerability. There are no workarounds that address this vulnerability.
History

Fri, 15 Nov 2024 21:15:00 +0000

Type Values Removed Values Added
First Time appeared Cisco
Cisco ata 190 Firmware
CPEs cpe:2.3:o:cisco:ata_190_firmware:*:*:*:*:*:*:*:*
Vendors & Products Cisco
Cisco ata 190 Firmware
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 15 Nov 2024 15:45:00 +0000

Type Values Removed Values Added
Description A vulnerability in the Cisco Discovery Protocol functionality of Cisco ATA 190 Series Adaptive Telephone Adapter firmware could allow an unauthenticated, remote attacker to cause a DoS condition on an affected device. This vulnerability is due to an out-of-bounds read when processing Cisco Discovery Protocol packets. An attacker could exploit this vulnerability by sending crafted Cisco Discovery Protocol packets to an affected device. A successful exploit could allow the attacker to cause a service restart.Cisco has released firmware updates that address this vulnerability. There are no workarounds that address this vulnerability.
Title Cisco ATA 190 Series Analog Telephone Adapter firmware Cisco Discovery Protocol Denial of Service Vulnerability
Weaknesses CWE-125
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L'}


cve-icon MITRE

Status: PUBLISHED

Assigner: cisco

Published: 2024-11-15T15:35:42.433Z

Updated: 2024-11-15T21:07:11.500Z

Reserved: 2021-11-02T13:28:29.102Z

Link: CVE-2022-20766

cve-icon Vulnrichment

Updated: 2024-11-15T21:06:55.388Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2024-11-15T16:15:22.133

Modified: 2024-11-18T17:11:56.587

Link: CVE-2022-20766

cve-icon Redhat

No data.