CVE-2022-20688
published 2022-12-12CVE-2022-20688: A vulnerability in the Cisco Discovery Protocol functionality of Cisco ATA 190 Series Analog Telephone Adapter firmware could allow an unauthenticated, remote…
PriorityP434medium5.3CVSS 3.1
AVNACLPRNUINSUCNINAL
EPSS
0.94%
56.6th percentile
A vulnerability in the Cisco Discovery Protocol functionality of Cisco ATA 190 Series Analog Telephone Adapter firmware could allow an unauthenticated, remote attacker to execute arbitrary code on an affected device and cause Cisco Discovery Protocol service to restart.
This vulnerability is due to missing length validation of certain Cisco Discovery Protocol packet header fields. An attacker could exploit these vulnerabilities by sending a malicious Cisco Discovery Protocol packet to an affected device. A successful exploit could allow the attacker to execute code on the affected device and cause Cisco Discovery Protocol to restart unexpectedly, resulting in a DoS condition.
Affected
23 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | ata_190_series_analog_telephone_adapter | — | — |
| cisco | ata_191_firmware | < 11.2.2 | 11.2.2 |
| cisco | ata_191_firmware | < 12.0.1 | 12.0.1 |
| cisco | ata_191_firmware | — | — |
| cisco | ata_192_firmware | < 11.2.2 | 11.2.2 |
| cisco | cisco_analog_telephone_adaptor_software | — | — |
| cisco | cisco_analog_telephone_adaptor_software | — | — |
| cisco | cisco_analog_telephone_adaptor_software | — | — |
| cisco | cisco_analog_telephone_adaptor_software | — | — |
| cisco | cisco_analog_telephone_adaptor_software | — | — |
| cisco | cisco_analog_telephone_adaptor_software | — | — |
| cisco | cisco_analog_telephone_adaptor_software | — | — |
| cisco | cisco_analog_telephone_adaptor_software | — | — |
| cisco | cisco_analog_telephone_adaptor_software | — | — |
| cisco | cisco_analog_telephone_adaptor_software | — | — |
| cisco | cisco_analog_telephone_adaptor_software | — | — |
| cisco | cisco_analog_telephone_adaptor_software | — | — |
| cisco | cisco_analog_telephone_adaptor_software | — | — |
| cisco | cisco_analog_telephone_adaptor_software | — | — |
| cisco | cisco_analog_telephone_adaptor_software | — | — |
| cisco | cisco_analog_telephone_adaptor_software | — | — |
| cisco | cisco_analog_telephone_adaptor_software | — | — |
| cisco | cisco_analog_telephone_adaptor_software | — | — |
CVSS provenance
nvdv3.15.3MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
vendor_cisco5.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Cisco
Cisco ATA 190 Series Analog Telephone Adapter Software Vulnerabilities
vendor_cisco·2022-10-05·CVSS 5.3
CVE-2022-20686 [MEDIUM] CWE-120 Cisco ATA 190 Series Analog Telephone Adapter Software Vulnerabilities
Cisco ATA 190 Series Analog Telephone Adapter Software Vulnerabilities
Multiple vulnerabilities in the Cisco Discovery Protocol and Link Layer Discovery Protocol (LLDP) for Cisco ATA 190 Series Analog Telephone Adapter Software could allow an attacker to execute code, cause the service to reload unexpectedly, or cause Cisco Discovery Protocol or LLDP database corruption on an affected device.
Note: Cisco Discovery Protocol and LLDP are a Layer 2 protocols. To exploit these vulnerabilities, an attacker must be in the same broadcast domain as the affected device (Layer 2 adjacent).
For more information about these vulnerabilities, see the Details section of this advisory.
Cisco has released software updates that address these vulnerabilities. There are no workarounds that address these vuln
Cisco
Cisco ATA 190 Series Analog Telephone Adapter Software Vulnerabilities
vendor_cisco·CVSS 3.1
CVE-2022-20688 Cisco ATA 190 Series Analog Telephone Adapter Software Vulnerabilities
CVE-2022-20688: Cisco ATA 190 Series Analog Telephone Adapter Software Vulnerabilities
Multiple vulnerabilities in the Cisco Discovery Protocol and Link Layer Discovery Protocol (LLDP) for Cisco ATA 190 Series Analog Telephone Adapter Software could allow an attacker to execute code, cause the service to reload unexpectedly, or cause Cisco Discovery Protocol or LLDP database corruption on an affected device. Note: Cisco Discovery Protocol and LLDP are a Layer 2 protocols. To exploit these vulnerabilities, an attacker must be in the same broadcast domain as the affected device (Layer 2 adjacent). For more information about these vulnerabilities, see the
CVSS: 3.1
CWE: CWE-120, CWE-125, CWE-130, CWE-120, CWE-125, CWE-130, CWE-400, CWE-120, CWE-125, CWE-130, CWE-120, CWE-125, CWE-130, CWE-400
GHSA
GHSA-5jj8-q8mr-r2vw: A vulnerability in the Cisco Discovery Protocol functionality of Cisco ATA 190 Series Analog Telephone Adapter firmware could allow an unauthenticated
ghsa_unreviewed·2022-12-12
CVE-2022-20688 [MEDIUM] CWE-125 GHSA-5jj8-q8mr-r2vw: A vulnerability in the Cisco Discovery Protocol functionality of Cisco ATA 190 Series Analog Telephone Adapter firmware could allow an unauthenticated
A vulnerability in the Cisco Discovery Protocol functionality of Cisco ATA 190 Series Analog Telephone Adapter firmware could allow an unauthenticated, remote attacker to execute arbitrary code on an affected device and cause Cisco Discovery Protocol service to restart. This vulnerability is due to missing length validation of certain Cisco Discovery Protocol packet header fields. An attacker could exploit these vulnerabilities by sending a malicious Cisco Discovery Protocol packet to an affected device. A successful exploit could allow the attacker to execute code on the affected device and cause Cisco Discovery Protocol to restart unexpectedly, resulting in a DoS condition.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2022-12-12
Published