This vulnerability is due to insufficient input validation of received Cisco Discovery Protocol packets. An attacker could exploit this vulnerability by sending crafted Cisco Discovery Protocol traffic to an affected device. A successful exploit could allow the attacker to cause a stack overflow, resulting in possible remote code execution or a denial of service (DoS) condition on an affected device.
Metrics
No CVSS v4.0
Attack Vector Adjacent Network
Attack Complexity Low
Privileges Required None
Scope Unchanged
Confidentiality Impact None
Integrity Impact High
Availability Impact High
User Interaction None
No CVSS v3.0
No CVSS v2
This CVE is not in the KEV list.
The EPSS score is 0.04695.
Key SSVC decision points have not yet been added.
Affected Vendors & Products
| Vendors | Products |
|---|---|
|
Cisco
Subscribe
|
Ip Phone 7811
Subscribe
Ip Phone 7811 Firmware
Subscribe
Ip Phone 7821
Subscribe
Ip Phone 7821 Firmware
Subscribe
Ip Phone 7832
Subscribe
Ip Phone 7832 Firmware
Subscribe
Ip Phone 7841
Subscribe
Ip Phone 7841 Firmware
Subscribe
Ip Phone 7861
Subscribe
Ip Phone 7861 Firmware
Subscribe
Ip Phone 8811
Subscribe
Ip Phone 8811 Firmware
Subscribe
Ip Phone 8831
Subscribe
Ip Phone 8831 Firmware
Subscribe
Ip Phone 8832
Subscribe
Ip Phone 8832 Firmware
Subscribe
Ip Phone 8841
Subscribe
Ip Phone 8841 Firmware
Subscribe
Ip Phone 8845
Subscribe
Ip Phone 8845 Firmware
Subscribe
Ip Phone 8851
Subscribe
Ip Phone 8851 Firmware
Subscribe
Ip Phone 8861
Subscribe
Ip Phone 8861 Firmware
Subscribe
Ip Phone 8865
Subscribe
Ip Phone 8865 Firmware
Subscribe
|
Configuration 1 [-]
| AND |
|
Configuration 2 [-]
| AND |
|
Configuration 3 [-]
| AND |
|
Configuration 4 [-]
| AND |
|
Configuration 5 [-]
| AND |
|
Configuration 6 [-]
| AND |
|
Configuration 7 [-]
| AND |
|
Configuration 8 [-]
| AND |
|
Configuration 9 [-]
| AND |
|
Configuration 10 [-]
| AND |
|
Configuration 11 [-]
| AND |
|
Configuration 12 [-]
| AND |
|
Configuration 13 [-]
| AND |
|
No data.
No data.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2022-26218 | A vulnerability in the Cisco Discovery Protocol processing feature of Cisco IP Phone 7800 and 8800 Series firmware could allow an unauthenticated, adjacent attacker to cause a stack overflow on an affected device. This vulnerability is due to insufficient input validation of received Cisco Discovery Protocol packets. An attacker could exploit this vulnerability by sending crafted Cisco Discovery Protocol traffic to an affected device. A successful exploit could allow the attacker to cause a stack overflow, resulting in possible remote code execution or a denial of service (DoS) condition on an affected device. |
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
No history.
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: cisco
Published:
Updated: 2024-08-03T02:31:58.569Z
Reserved: 2021-11-02T13:28:29.197Z
Link: CVE-2022-20968
No data.
Status : Modified
Published: 2022-12-12T09:15:12.613
Modified: 2024-11-21T06:43:56.270
Link: CVE-2022-20968
No data.
OpenCVE Enrichment
No data.
EUVD