First published: Wed Feb 05 2020(Updated: )
A vulnerability in the Cisco Discovery Protocol implementation for the Cisco IP Phone could allow an unauthenticated, adjacent attacker to remotely execute code with root privileges or cause a reload of an affected IP phone. The vulnerability is due to missing checks when processing Cisco Discovery Protocol messages. An attacker could exploit this vulnerability by sending a crafted Cisco Discovery Protocol packet to the targeted IP phone. A successful exploit could allow the attacker to remotely execute code with root privileges or cause a reload of an affected IP phone, resulting in a denial of service (DoS) condition. Cisco Discovery Protocol is a Layer 2 protocol. To exploit this vulnerability, an attacker must be in the same broadcast domain as the affected device (Layer 2 adjacent).
Credit: ykramarz@cisco.com
Affected Software | Affected Version | How to fix |
---|---|---|
Cisco Ip Conference Phone 7832 Firmware | <12.7\(1\) | |
Cisco Ip Conference Phone 7832 With Multiplatform Firmware | <11.3\(1\)sr1 | |
Cisco Ip Conference Phone 7832 | ||
Cisco Ip Conference Phone 8832 Firmware | <12.7\(1\) | |
Cisco Ip Conference Phone 8832 With Multiplatform Firmware | <11.3\(1\)sr1 | |
Cisco Ip Conference Phone 8832 | ||
Cisco Ip Phone 6821 Firmware | <11.3\(1\)sr1 | |
Cisco Ip Phone 6821 | ||
Cisco Ip Phone 6841 Firmware | <11.3\(1\)sr1 | |
Cisco Ip Phone 6841 | ||
Cisco Ip Phone 6851 Firmware | <11.3\(1\)sr1 | |
Cisco Ip Phone 6851 | ||
Cisco Ip Phone 6861 Firmware | <11.3\(1\)sr1 | |
Cisco Ip Phone 6861 | ||
Cisco Ip Phone 6871 Firmware | <11.3\(1\)sr1 | |
Cisco Ip Phone 6871 | ||
Cisco Ip Phone 7811 Firmware | <12.7\(1\) | |
Cisco Ip Phone 7811 With Multiplatform Firmware | <11.3\(1\)sr1 | |
Cisco Ip Phone 7811 | ||
Cisco Ip Phone 7821 Firmware | <12.7\(1\) | |
Cisco Ip Phone 7821 With Multiplatform Firmware | <11.3\(1\)sr1 | |
Cisco Ip Phone 7821 | ||
Cisco Ip Phone 7841 Firmware | <12.7\(1\) | |
Cisco Ip Phone 7841 With Multiplatform Firmware | <11.3\(1\)sr1 | |
Cisco Ip Phone 7841 | ||
Cisco Ip Phone 7861 Firmware | <12.7\(1\) | |
Cisco Ip Phone 7861 With Multiplatform Firmware | <11.3\(1\)sr1 | |
Cisco IP Phone 7861 | ||
Cisco Ip Phone 8811 Firmware | <12.7\(1\) | |
Cisco Ip Phone 8811 With Multiplatform Firmware | <11.3\(1\)sr1 | |
Cisco Ip Phone 8811 | ||
Cisco Ip Phone 8841 Firmware | <12.7\(1\) | |
Cisco Ip Phone 8841 With Multiplatform Firmware | <11.3\(1\)sr1 | |
Cisco Ip Phone 8841 | ||
Cisco Ip Phone 8851 Firmware | <12.7\(1\) | |
Cisco Ip Phone 8851 With Multiplatform Firmware | <11.3\(1\)sr1 | |
Cisco IP Phone 8851 | ||
Cisco Ip Phone 8861 Firmware | <12.7\(1\) | |
Cisco Ip Phone 8861 With Multiplatform Firmware | <11.3\(1\)sr1 | |
Cisco Ip Phone 8861 | ||
Cisco Ip Phone 8845 Firmware | <12.7\(1\) | |
Cisco Ip Phone 8845 With Multiplatform Firmware | <11.3\(1\)sr1 | |
Cisco Ip Phone 8845 | ||
Cisco Ip Phone 8865 Firmware | <12.7\(1\) | |
Cisco Ip Phone 8865 With Multiplatform Firmware | <11.3\(1\)sr1 | |
Cisco Ip Phone 8865 | ||
Cisco Unified Ip Conference Phone 8831 Firmware | <10.3\(1\)sr6 | |
Cisco Unified Ip Conference Phone 8831 | ||
Cisco Unified Ip Conference Phone 8831 For Third-party Call Control Firmware | ||
Cisco Unified Ip Conference Phone 8831 For Third-party Call Control | ||
Cisco Wireless Ip Phone 8821 Firmware | <11.0\(5\)sr2 | |
Cisco Wireless Ip Phone 8821 | ||
Cisco Wireless Ip Phone 8821-ex Firmware | <11.0\(5\)sr2 | |
Cisco Wireless Ip Phone 8821-ex |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this vulnerability is CVE-2020-3111.
The severity of CVE-2020-3111 is high with a CVSS score of 8.8.
The affected software for CVE-2020-3111 includes various Cisco IP Phone models with specific firmware versions.
An attacker can exploit CVE-2020-3111 by sending maliciously crafted packets to an affected Cisco IP Phone.
The recommended mitigation for CVE-2020-3111 is to apply the necessary security updates provided by Cisco.