Severity
High
Analysis Summary
The vulnerability is due to missing checks when processing Cisco Discovery Protocol messages. An attacker could exploit this vulnerability by sending a crafted Cisco Discovery Protocol packet to the targeted IP phone. A successful exploit could allow the attacker to remotely execute code with root privileges or cause a reload of an affected IP phone, resulting in a denial of service (DoS) condition.
Impact
- Denial of service
- Remote code execution
Affected Vendors
Cisco
Remediation
Please refer to vendor’s advisory for the list of affected products and upgraded patches.