CVE-2022-20690
published 2022-12-12CVE-2022-20690: Multiple vulnerabilities in the Cisco Discovery Protocol functionality of Cisco ATA 190 Series Analog Telephone Adapter firmware could allow an…
PriorityP351high8.8CVSS 3.1
AVAACLPRNUINSUCHIHAH
EPSS
0.73%
49.8th percentile
Multiple vulnerabilities in the Cisco Discovery Protocol functionality of Cisco ATA 190 Series Analog Telephone Adapter firmware could allow an unauthenticated, adjacent attacker to cause Cisco Discovery Protocol memory corruption on an affected device.
These vulnerabilities are due to missing length validation checks when processing Cisco Discovery Protocol messages. An attacker could exploit these vulnerabilities by sending a malicious Cisco Discovery Protocol packet to an affected device. A successful exploit could allow the attacker to cause an out-of-bounds read of the valid Cisco Discovery Protocol packet data, which could allow the attacker to cause corruption in the internal Cisco Discovery Protocol database of the affected device.
Affected
23 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | ata_190_series_analog_telephone_adapter | — | — |
| cisco | ata_191_firmware | < 11.2.2 | 11.2.2 |
| cisco | ata_191_firmware | < 12.0.1 | 12.0.1 |
| cisco | ata_191_firmware | — | — |
| cisco | ata_192_firmware | < 11.2.2 | 11.2.2 |
| cisco | cisco_analog_telephone_adaptor_software | — | — |
| cisco | cisco_analog_telephone_adaptor_software | — | — |
| cisco | cisco_analog_telephone_adaptor_software | — | — |
| cisco | cisco_analog_telephone_adaptor_software | — | — |
| cisco | cisco_analog_telephone_adaptor_software | — | — |
| cisco | cisco_analog_telephone_adaptor_software | — | — |
| cisco | cisco_analog_telephone_adaptor_software | — | — |
| cisco | cisco_analog_telephone_adaptor_software | — | — |
| cisco | cisco_analog_telephone_adaptor_software | — | — |
| cisco | cisco_analog_telephone_adaptor_software | — | — |
| cisco | cisco_analog_telephone_adaptor_software | — | — |
| cisco | cisco_analog_telephone_adaptor_software | — | — |
| cisco | cisco_analog_telephone_adaptor_software | — | — |
| cisco | cisco_analog_telephone_adaptor_software | — | — |
| cisco | cisco_analog_telephone_adaptor_software | — | — |
| cisco | cisco_analog_telephone_adaptor_software | — | — |
| cisco | cisco_analog_telephone_adaptor_software | — | — |
| cisco | cisco_analog_telephone_adaptor_software | — | — |
CVSS provenance
nvdv3.18.8HIGHCVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
vendor_cisco5.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Cisco
Cisco ATA 190 Series Analog Telephone Adapter Software Vulnerabilities
vendor_cisco·2022-10-05·CVSS 5.3
CVE-2022-20686 [MEDIUM] CWE-120 Cisco ATA 190 Series Analog Telephone Adapter Software Vulnerabilities
Cisco ATA 190 Series Analog Telephone Adapter Software Vulnerabilities
Multiple vulnerabilities in the Cisco Discovery Protocol and Link Layer Discovery Protocol (LLDP) for Cisco ATA 190 Series Analog Telephone Adapter Software could allow an attacker to execute code, cause the service to reload unexpectedly, or cause Cisco Discovery Protocol or LLDP database corruption on an affected device.
Note: Cisco Discovery Protocol and LLDP are a Layer 2 protocols. To exploit these vulnerabilities, an attacker must be in the same broadcast domain as the affected device (Layer 2 adjacent).
For more information about these vulnerabilities, see the Details section of this advisory.
Cisco has released software updates that address these vulnerabilities. There are no workarounds that address these vuln
Cisco
Cisco ATA 190 Series Analog Telephone Adapter Software Vulnerabilities
vendor_cisco·CVSS 3.1
CVE-2022-20690 Cisco ATA 190 Series Analog Telephone Adapter Software Vulnerabilities
CVE-2022-20690: Cisco ATA 190 Series Analog Telephone Adapter Software Vulnerabilities
Multiple vulnerabilities in the Cisco Discovery Protocol and Link Layer Discovery Protocol (LLDP) for Cisco ATA 190 Series Analog Telephone Adapter Software could allow an attacker to execute code, cause the service to reload unexpectedly, or cause Cisco Discovery Protocol or LLDP database corruption on an affected device. Note: Cisco Discovery Protocol and LLDP are a Layer 2 protocols. To exploit these vulnerabilities, an attacker must be in the same broadcast domain as the affected device (Layer 2 adjacent). For more information about these vulnerabilities, see the
CVSS: 3.1
CWE: CWE-120, CWE-125, CWE-130, CWE-120, CWE-125, CWE-130, CWE-400, CWE-120, CWE-125, CWE-130, CWE-120, CWE-125, CWE-130, CWE-400
GHSA
GHSA-wcr3-8jhg-v89r: Multiple vulnerabilities in the Cisco Discovery Protocol functionality of Cisco ATA 190 Series Analog Telephone Adapter firmware could allow an unauth
ghsa_unreviewed·2022-12-12
CVE-2022-20690 [HIGH] CWE-1284 GHSA-wcr3-8jhg-v89r: Multiple vulnerabilities in the Cisco Discovery Protocol functionality of Cisco ATA 190 Series Analog Telephone Adapter firmware could allow an unauth
Multiple vulnerabilities in the Cisco Discovery Protocol functionality of Cisco ATA 190 Series Analog Telephone Adapter firmware could allow an unauthenticated, adjacent attacker to cause Cisco Discovery Protocol memory corruption on an affected device. These vulnerabilities are due to missing length validation checks when processing Cisco Discovery Protocol messages. An attacker could exploit these vulnerabilities by sending a malicious Cisco Discovery Protocol packet to an affected device. A successful exploit could allow the attacker to cause an out-of-bounds read of the valid Cisco Discovery Protocol packet data, which could allow the attacker to cause corruption in the internal Cisco Discovery Protocol database of the affected device.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2022-12-12
Published