Cisco IP Phone Security Update 11 December 2022

Cisco has released a security update to fix a vulnerability in Cisco IP Phone 7800 and 8800 Series firmware.

The addressed vulnerability could allow the unauthenticated attacker to exploit this vulnerability by sending crafted Cisco Discovery Protocol traffic to the affected device to cause a stack overflow, resulting in possible remote code execution or a denial of service (DoS) condition on the affected device.

Cisco IP Phone 7800 and 8800 Series firmware buffer overflow (CVE-2022-20968):

  • CVSS: 8.1
  • Attack Vector: Adjacent Network
  • Attack Complexity: Low
  • Privileges Required: None
  • User Interaction: None
  • Consequences: Gain Access
Vulnerabilities
  • CVE-2022-20968
Mitigations

The enterprise should deploy this patch as soon as the testing phase is completed.

Cisco Security Advisory

References