CVE-2022-20686
published 2022-12-12CVE-2022-20686: Multiple vulnerabilities in the Link Layer Discovery Protocol (LLDP) functionality of Cisco ATA 190 Series Analog Telephone Adapter firmware could allow an…
PriorityP433medium5.3CVSS 3.1
AVNACLPRNUINSUCNINAL
EPSS
0.93%
56.3th percentile
Multiple vulnerabilities in the Link Layer Discovery Protocol (LLDP) functionality of Cisco ATA 190 Series Analog Telephone Adapter firmware could allow an unauthenticated, remote attacker to execute arbitrary code on an affected device and cause the LLDP service to restart.
These vulnerabilities are due to missing length validation of certain LLDP packet header fields. An attacker could exploit these vulnerabilities by sending a malicious LLDP packet to an affected device. A successful exploit could allow the attacker to execute code on the affected device and cause LLDP to restart unexpectedly, resulting in a denial of service (DoS) condition.
Affected
23 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | ata_190_series_analog_telephone_adapter | — | — |
| cisco | ata_191_firmware | < 11.2.2 | 11.2.2 |
| cisco | ata_191_firmware | < 12.0.1 | 12.0.1 |
| cisco | ata_191_firmware | — | — |
| cisco | ata_192_firmware | < 11.2.2 | 11.2.2 |
| cisco | cisco_analog_telephone_adaptor_software | — | — |
| cisco | cisco_analog_telephone_adaptor_software | — | — |
| cisco | cisco_analog_telephone_adaptor_software | — | — |
| cisco | cisco_analog_telephone_adaptor_software | — | — |
| cisco | cisco_analog_telephone_adaptor_software | — | — |
| cisco | cisco_analog_telephone_adaptor_software | — | — |
| cisco | cisco_analog_telephone_adaptor_software | — | — |
| cisco | cisco_analog_telephone_adaptor_software | — | — |
| cisco | cisco_analog_telephone_adaptor_software | — | — |
| cisco | cisco_analog_telephone_adaptor_software | — | — |
| cisco | cisco_analog_telephone_adaptor_software | — | — |
| cisco | cisco_analog_telephone_adaptor_software | — | — |
| cisco | cisco_analog_telephone_adaptor_software | — | — |
| cisco | cisco_analog_telephone_adaptor_software | — | — |
| cisco | cisco_analog_telephone_adaptor_software | — | — |
| cisco | cisco_analog_telephone_adaptor_software | — | — |
| cisco | cisco_analog_telephone_adaptor_software | — | — |
| cisco | cisco_analog_telephone_adaptor_software | — | — |
CVSS provenance
nvdv3.15.3MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
vendor_cisco5.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Cisco
Cisco ATA 190 Series Analog Telephone Adapter Software Vulnerabilities
vendor_cisco·2022-10-05·CVSS 5.3
CVE-2022-20686 [MEDIUM] CWE-120 Cisco ATA 190 Series Analog Telephone Adapter Software Vulnerabilities
Cisco ATA 190 Series Analog Telephone Adapter Software Vulnerabilities
Multiple vulnerabilities in the Cisco Discovery Protocol and Link Layer Discovery Protocol (LLDP) for Cisco ATA 190 Series Analog Telephone Adapter Software could allow an attacker to execute code, cause the service to reload unexpectedly, or cause Cisco Discovery Protocol or LLDP database corruption on an affected device.
Note: Cisco Discovery Protocol and LLDP are a Layer 2 protocols. To exploit these vulnerabilities, an attacker must be in the same broadcast domain as the affected device (Layer 2 adjacent).
For more information about these vulnerabilities, see the Details section of this advisory.
Cisco has released software updates that address these vulnerabilities. There are no workarounds that address these vuln
Cisco
Cisco ATA 190 Series Analog Telephone Adapter Software Vulnerabilities
vendor_cisco·CVSS 3.1
CVE-2022-20686 Cisco ATA 190 Series Analog Telephone Adapter Software Vulnerabilities
CVE-2022-20686: Cisco ATA 190 Series Analog Telephone Adapter Software Vulnerabilities
Multiple vulnerabilities in the Cisco Discovery Protocol and Link Layer Discovery Protocol (LLDP) for Cisco ATA 190 Series Analog Telephone Adapter Software could allow an attacker to execute code, cause the service to reload unexpectedly, or cause Cisco Discovery Protocol or LLDP database corruption on an affected device. Note: Cisco Discovery Protocol and LLDP are a Layer 2 protocols. To exploit these vulnerabilities, an attacker must be in the same broadcast domain as the affected device (Layer 2 adjacent). For more information about these vulnerabilities, see the
CVSS: 3.1
CWE: CWE-120, CWE-125, CWE-130, CWE-120, CWE-125, CWE-130, CWE-400, CWE-120, CWE-125, CWE-130, CWE-120, CWE-125, CWE-130, CWE-400
GHSA
GHSA-gx9f-qvh7-6mrg: Multiple vulnerabilities in the Link Layer Discovery Protocol (LLDP) functionality of Cisco ATA 190 Series Analog Telephone Adapter firmware could all
ghsa_unreviewed·2022-12-12
CVE-2022-20686 [MEDIUM] CWE-1284 GHSA-gx9f-qvh7-6mrg: Multiple vulnerabilities in the Link Layer Discovery Protocol (LLDP) functionality of Cisco ATA 190 Series Analog Telephone Adapter firmware could all
Multiple vulnerabilities in the Link Layer Discovery Protocol (LLDP) functionality of Cisco ATA 190 Series Analog Telephone Adapter firmware could allow an unauthenticated, remote attacker to execute arbitrary code on an affected device and cause the LLDP service to restart. These vulnerabilities are due to missing length validation of certain LLDP packet header fields. An attacker could exploit these vulnerabilities by sending a malicious LLDP packet to an affected device. A successful exploit could allow the attacker to execute code on the affected device and cause LLDP to restart unexpectedly, resulting in a denial of service (DoS) condition.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2022-12-12
Published