CVE-2022-20766
published 2024-11-15CVE-2022-20766: A vulnerability in the Cisco Discovery Protocol functionality of Cisco ATA 190 Series Adaptive Telephone Adapter firmware could allow an unauthenticated…
PriorityP430medium5.3CVSS 3.1
AVNACLPRNUINSUCNINAL
EPSS
0.82%
53.1th percentile
A vulnerability in the Cisco Discovery Protocol functionality of Cisco ATA 190 Series Adaptive Telephone Adapter firmware could allow an unauthenticated, remote attacker to cause a DoS condition on an affected device.
This vulnerability is due to an out-of-bounds read when processing Cisco Discovery Protocol packets. An attacker could exploit this vulnerability by sending crafted Cisco Discovery Protocol packets to an affected device. A successful exploit could allow the attacker to cause a service restart.Cisco has released firmware updates that address this vulnerability. There are no workarounds that address this vulnerability.
Affected
39 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | ata_190_series_analog_telephone_adapter | — | — |
| cisco | cisco_analog_telephone_adaptor_software | — | — |
| cisco | cisco_analog_telephone_adaptor_software | — | — |
| cisco | cisco_analog_telephone_adaptor_software | — | — |
| cisco | cisco_analog_telephone_adaptor_software | — | — |
| cisco | cisco_analog_telephone_adaptor_software | — | — |
| cisco | cisco_analog_telephone_adaptor_software | — | — |
| cisco | cisco_analog_telephone_adaptor_software | — | — |
| cisco | cisco_analog_telephone_adaptor_software | — | — |
| cisco | cisco_analog_telephone_adaptor_software | — | — |
| cisco | cisco_analog_telephone_adaptor_software | — | — |
| cisco | cisco_analog_telephone_adaptor_software | — | — |
| cisco | cisco_analog_telephone_adaptor_software | — | — |
| cisco | cisco_analog_telephone_adaptor_software | — | — |
| cisco | cisco_analog_telephone_adaptor_software | — | — |
| cisco | cisco_analog_telephone_adaptor_software | — | — |
| cisco | cisco_analog_telephone_adaptor_software | — | — |
| cisco | cisco_analog_telephone_adaptor_software | — | — |
| cisco | cisco_analog_telephone_adaptor_software | — | — |
| cisco | cisco_analog_telephone_adaptor_software | — | — |
| cisco | cisco_analog_telephone_adaptor_software | — | — |
| cisco | cisco_analog_telephone_adaptor_software | — | — |
| cisco | cisco_analog_telephone_adaptor_software | — | — |
| cisco | cisco_analog_telephone_adaptor_software | — | — |
| cisco | cisco_analog_telephone_adaptor_software | — | — |
CVSS provenance
nvdv3.15.3MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
vendor_cisco5.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Cisco
Cisco ATA 190 Series Analog Telephone Adapter Software Vulnerabilities
vendor_cisco·2022-10-05·CVSS 5.3
CVE-2022-20686 [MEDIUM] CWE-120 Cisco ATA 190 Series Analog Telephone Adapter Software Vulnerabilities
Cisco ATA 190 Series Analog Telephone Adapter Software Vulnerabilities
Multiple vulnerabilities in the Cisco Discovery Protocol and Link Layer Discovery Protocol (LLDP) for Cisco ATA 190 Series Analog Telephone Adapter Software could allow an attacker to execute code, cause the service to reload unexpectedly, or cause Cisco Discovery Protocol or LLDP database corruption on an affected device.
Note: Cisco Discovery Protocol and LLDP are a Layer 2 protocols. To exploit these vulnerabilities, an attacker must be in the same broadcast domain as the affected device (Layer 2 adjacent).
For more information about these vulnerabilities, see the Details section of this advisory.
Cisco has released software updates that address these vulnerabilities. There are no workarounds that address these vuln
Cisco
Cisco ATA 190 Series Analog Telephone Adapter Software Vulnerabilities
vendor_cisco·CVSS 3.1
CVE-2022-20766 Cisco ATA 190 Series Analog Telephone Adapter Software Vulnerabilities
CVE-2022-20766: Cisco ATA 190 Series Analog Telephone Adapter Software Vulnerabilities
Multiple vulnerabilities in the Cisco Discovery Protocol and Link Layer Discovery Protocol (LLDP) for Cisco ATA 190 Series Analog Telephone Adapter Software could allow an attacker to execute code, cause the service to reload unexpectedly, or cause Cisco Discovery Protocol or LLDP database corruption on an affected device. Note: Cisco Discovery Protocol and LLDP are a Layer 2 protocols. To exploit these vulnerabilities, an attacker must be in the same broadcast domain as the affected device (Layer 2 adjacent). For more information about these vulnerabilities, see the
CVSS: 3.1
CWE: CWE-120, CWE-125, CWE-130, CWE-120, CWE-125, CWE-130, CWE-400, CWE-120, CWE-125, CWE-130, CWE-120, CWE-125, CWE-130, CWE-400
GHSA
GHSA-7q63-79xq-2jj4: A vulnerability in the Cisco Discovery Protocol functionality of Cisco ATA 190 Series Adaptive Telephone Adapter firmware could allow an unauthenticat
ghsa_unreviewed·2024-11-15
CVE-2022-20766 [MEDIUM] CWE-125 GHSA-7q63-79xq-2jj4: A vulnerability in the Cisco Discovery Protocol functionality of Cisco ATA 190 Series Adaptive Telephone Adapter firmware could allow an unauthenticat
A vulnerability in the Cisco Discovery Protocol functionality of Cisco ATA 190 Series Adaptive Telephone Adapter firmware could allow an unauthenticated, remote attacker to cause a DoS condition on an affected device.
This vulnerability is due to an out-of-bounds read when processing Cisco Discovery Protocol packets. An attacker could exploit this vulnerability by sending crafted Cisco Discovery Protocol packets to an affected device. A successful exploit could allow the attacker to cause a service restart.Cisco has released firmware updates that address this vulnerability. There are no workarounds that address this vulnerability.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2024-11-15
Published