Memory Corruption Vulnerability in Cisco ATA 190 Series Analog Telephone Adapter
CVE-2022-20689
Summary
The vulnerability in the Cisco Discovery Protocol within Cisco ATA 190 Series Analog Telephone Adapter firmware allows unauthenticated, adjacent attackers to exploit memory management flaws. This flaw is caused by insufficient length validation when processing Cisco Discovery Protocol messages. By sending specially crafted packets, attackers could induce out-of-bounds reads, compromising the integrity of the internal Cisco Discovery Protocol database on the device. This could lead to various adverse effects on the operation of the affected device.
Affected Version(s)
Cisco Analog Telephone Adaptor (ATA) Software 1.2.1
Cisco Analog Telephone Adaptor (ATA) Software 1.2.2 SR1
Cisco Analog Telephone Adaptor (ATA) Software 1.2.2
References
CVSS V3.1
Timeline
- 👾
Exploit known to exist
Vulnerability published
Vulnerability Reserved