Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-39vj-2wxm-c37w

Опубликовано: 12 дек. 2022
Источник: github
Github: Не прошло ревью
CVSS3: 8.8

Описание

A vulnerability in the Cisco Discovery Protocol processing feature of Cisco IP Phone 7800 and 8800 Series firmware could allow an unauthenticated, adjacent attacker to cause a stack overflow on an affected device. This vulnerability is due to insufficient input validation of received Cisco Discovery Protocol packets. An attacker could exploit this vulnerability by sending crafted Cisco Discovery Protocol traffic to an affected device. A successful exploit could allow the attacker to cause a stack overflow, resulting in possible remote code execution or a denial of service (DoS) condition on an affected device.

A vulnerability in the Cisco Discovery Protocol processing feature of Cisco IP Phone 7800 and 8800 Series firmware could allow an unauthenticated, adjacent attacker to cause a stack overflow on an affected device. This vulnerability is due to insufficient input validation of received Cisco Discovery Protocol packets. An attacker could exploit this vulnerability by sending crafted Cisco Discovery Protocol traffic to an affected device. A successful exploit could allow the attacker to cause a stack overflow, resulting in possible remote code execution or a denial of service (DoS) condition on an affected device.

EPSS

Процентиль: 93%
0.10157
Средний

8.8 High

CVSS3

Дефекты

CWE-787

Связанные уязвимости

CVSS3: 8.1
nvd
около 3 лет назад

A vulnerability in the Cisco Discovery Protocol processing feature of Cisco IP Phone 7800 and 8800 Series firmware could allow an unauthenticated, adjacent attacker to cause a stack overflow on an affected device. This vulnerability is due to insufficient input validation of received Cisco Discovery Protocol packets. An attacker could exploit this vulnerability by sending crafted Cisco Discovery Protocol traffic to an affected device. A successful exploit could allow the attacker to cause a stack overflow, resulting in possible remote code execution or a denial of service (DoS) condition on an affected device.

CVSS3: 8.1
fstec
около 3 лет назад

Уязвимость функции обработки протокола Cisco Discovery микропрограммного обеспечения IP-телефонов Cisco IP Phone 7800, Cisco IP Phone 8800, позволяющая нарушителю выполнить произвольный код или вызвать отказ в обслуживании

EPSS

Процентиль: 93%
0.10157
Средний

8.8 High

CVSS3

Дефекты

CWE-787