8.8

CVE-2020-3111

A vulnerability in the Cisco Discovery Protocol implementation for the Cisco IP Phone could allow an unauthenticated, adjacent attacker to remotely execute code with root privileges or cause a reload of an affected IP phone. The vulnerability is due to missing checks when processing Cisco Discovery Protocol messages. An attacker could exploit this vulnerability by sending a crafted Cisco Discovery Protocol packet to the targeted IP phone. A successful exploit could allow the attacker to remotely execute code with root privileges or cause a reload of an affected IP phone, resulting in a denial of service (DoS) condition. Cisco Discovery Protocol is a Layer 2 protocol. To exploit this vulnerability, an attacker must be in the same broadcast domain as the affected device (Layer 2 adjacent).

Data is provided by the National Vulnerability Database (NVD)
CiscoIp Conference Phone 7832 Firmware Version < 12.7\(1\)
   CiscoIp Conference Phone 7832 Version-
CiscoIp Conference Phone 8832 Firmware Version < 12.7\(1\)
   CiscoIp Conference Phone 8832 Version-
CiscoIp Phone 6821 Firmware Version < 11.3\(1\)sr1
   CiscoIp Phone 6821 Version-
CiscoIp Phone 6841 Firmware Version < 11.3\(1\)sr1
   CiscoIp Phone 6841 Version-
CiscoIp Phone 6851 Firmware Version < 11.3\(1\)sr1
   CiscoIp Phone 6851 Version-
CiscoIp Phone 6861 Firmware Version < 11.3\(1\)sr1
   CiscoIp Phone 6861 Version-
CiscoIp Phone 6871 Firmware Version < 11.3\(1\)sr1
   CiscoIp Phone 6871 Version-
CiscoIp Phone 7811 Firmware Version < 12.7\(1\)
   CiscoIp Phone 7811 Version-
CiscoIp Phone 7811 With Multiplatform Firmware Version < 11.3\(1\)sr1
   CiscoIp Phone 7811 Version-
CiscoIp Phone 7821 Firmware Version < 12.7\(1\)
   CiscoIp Phone 7821 Version-
CiscoIp Phone 7821 With Multiplatform Firmware Version < 11.3\(1\)sr1
   CiscoIp Phone 7821 Version-
CiscoIp Phone 7841 Firmware Version < 12.7\(1\)
   CiscoIp Phone 7841 Version-
CiscoIp Phone 7841 With Multiplatform Firmware Version < 11.3\(1\)sr1
   CiscoIp Phone 7841 Version-
CiscoIp Phone 7861 Firmware Version < 12.7\(1\)
   CiscoIp Phone 7861 Version-
CiscoIp Phone 7861 With Multiplatform Firmware Version < 11.3\(1\)sr1
   CiscoIp Phone 7861 Version-
CiscoIp Phone 8811 Firmware Version < 12.7\(1\)
   CiscoIp Phone 8811 Version-
CiscoIp Phone 8811 With Multiplatform Firmware Version < 11.3\(1\)sr1
   CiscoIp Phone 8811 Version-
CiscoIp Phone 8841 Firmware Version < 12.7\(1\)
   CiscoIp Phone 8841 Version-
CiscoIp Phone 8841 With Multiplatform Firmware Version < 11.3\(1\)sr1
   CiscoIp Phone 8841 Version-
CiscoIp Phone 8851 Firmware Version < 12.7\(1\)
   CiscoIp Phone 8851 Version-
CiscoIp Phone 8851 With Multiplatform Firmware Version < 11.3\(1\)sr1
   CiscoIp Phone 8851 Version-
CiscoIp Phone 8861 Firmware Version < 12.7\(1\)
   CiscoIp Phone 8861 Version-
CiscoIp Phone 8861 With Multiplatform Firmware Version < 11.3\(1\)sr1
   CiscoIp Phone 8861 Version-
CiscoIp Phone 8845 Firmware Version < 12.7\(1\)
   CiscoIp Phone 8845 Version-
CiscoIp Phone 8845 With Multiplatform Firmware Version < 11.3\(1\)sr1
   CiscoIp Phone 8845 Version-
CiscoIp Phone 8865 Firmware Version < 12.7\(1\)
   CiscoIp Phone 8865 Version-
CiscoIp Phone 8865 With Multiplatform Firmware Version < 11.3\(1\)sr1
   CiscoIp Phone 8865 Version-
CiscoWireless Ip Phone 8821 Firmware Version < 11.0\(5\)sr2
   CiscoWireless Ip Phone 8821 Version-
CiscoWireless Ip Phone 8821-ex Firmware Version < 11.0\(5\)sr2
   CiscoWireless Ip Phone 8821-ex Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.23% 0.461
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 8.8 2.8 5.9
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvd@nist.gov 8.3 6.5 10
AV:A/AC:L/Au:N/C:C/I:C/A:C
psirt@cisco.com 8.8 2.8 5.9
CVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CWE-20 Improper Input Validation

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.