Lucene search

K
nvd[email protected]NVD:CVE-2022-20688
HistoryDec 12, 2022 - 9:15 a.m.

CVE-2022-20688

2022-12-1209:15:12
CWE-125
CWE-1284
web.nvd.nist.gov
cisco
ata 190
analog telephone adapter
vulnerability
remote attacker
arbitrary code
dos condition
cisco discovery protocol

5.3 Medium

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

LOW

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L

0.001 Low

EPSS

Percentile

47.0%

A vulnerability in the Cisco Discovery Protocol functionality of Cisco ATA 190 Series Analog Telephone Adapter firmware could allow an unauthenticated, remote attacker to execute arbitrary code on an affected device and cause Cisco Discovery Protocol service to restart.
This vulnerability is due to missing length validation of certain Cisco Discovery Protocol packet header fields. An attacker could exploit these vulnerabilities by sending a malicious Cisco Discovery Protocol packet to an affected device. A successful exploit could allow the attacker to execute code on the affected device and cause Cisco Discovery Protocol to restart unexpectedly, resulting in a DoS condition.

Affected configurations

NVD
Node
ciscoata_190_firmwareMatch-on-premises
AND
ciscoata_190Match-on-premises
Node
ciscoata_191_firmwareRange<11.2.2multiplatform
AND
ciscoata_191Match-multiplatform
Node
ciscoata_191_firmwareRange<12.0.1on-premises
OR
ciscoata_191_firmwareMatch12.0.1-on-premises
OR
ciscoata_191_firmwareMatch12.0.1sr1on-premises
OR
ciscoata_191_firmwareMatch12.0.1sr2on-premises
OR
ciscoata_191_firmwareMatch12.0.1sr3on-premises
OR
ciscoata_191_firmwareMatch12.0.1sr4on-premises
AND
ciscoata_191Match-on-premises
Node
ciscoata_192_firmwareRange<11.2.2multiplatform
AND
ciscoata_192Match-multiplatform

5.3 Medium

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

LOW

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L

0.001 Low

EPSS

Percentile

47.0%

Related for NVD:CVE-2022-20688