Multiple Vulnerabilities in Link Layer Discovery Protocol of Cisco ATA 190 Series
CVE-2022-20686
5.3MEDIUM
Summary
Multiple security vulnerabilities in the Link Layer Discovery Protocol (LLDP) of the Cisco ATA 190 Series Analog Telephone Adapter firmware may allow an unauthenticated, remote attacker to conduct arbitrary code execution. These weaknesses stem from inadequate validation of certain LLDP packet header fields. An attacker could send a specially crafted LLDP packet to an affected device, which would exploit these vulnerabilities, leading to unexpected LLDP service reboots and potentially resulting in a denial of service.
Affected Version(s)
Cisco Analog Telephone Adaptor (ATA) Software 1.2.1
Cisco Analog Telephone Adaptor (ATA) Software 1.2.2 SR1
Cisco Analog Telephone Adaptor (ATA) Software 1.2.2
References
CVSS V3.1
Score:
5.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
- 👾
Exploit known to exist
Vulnerability published
Vulnerability Reserved