CVE-2019-1684
MEDIUMCisco IP Phone 7800/8800 < 12.6(1)MN80 - DoS via Cisco Discovery Protocol or LLDP
Title source: llmDescription
A vulnerability in the Cisco Discovery Protocol or Link Layer Discovery Protocol (LLDP) implementation for the Cisco IP Phone 7800 and 8800 Series could allow an unauthenticated, adjacent attacker to cause an affected phone to reload unexpectedly, resulting in a temporary denial of service (DoS) condition. The vulnerability is due to missing length validation of certain Cisco Discovery Protocol or LLDP packet header fields. An attacker could exploit this vulnerability by sending a malicious Cisco Discovery Protocol or LLDP packet to the targeted phone. A successful exploit could allow the attacker to cause the affected phone to reload unexpectedly, resulting in a temporary DoS condition. Versions prior to 12.6(1)MN80 are affected.
References (2)
Core 2
Core References
Vendor Advisory vendor-advisory
x_refsource_cisco
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20190220-cdp-lldp-dos
Third Party Advisory, VDB Entry vdb-entry
x_refsource_bid
http://www.securityfocus.com/bid/107104
Scores
CVSS v3
6.5
EPSS
0.0064
EPSS Percentile
46.1%
Attack Vector
ADJACENT_NETWORK
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
partial
Details
CWE
CWE-119
CWE-399
Status
published
Products (14)
cisco/ip_conference_phone_7832_firmware
< 12.6\(1\)mn80
cisco/ip_conference_phone_8832_firmware
< 12.6\(1\)mn80
cisco/ip_phone_7800_firmware
< 12.6\(1\)mn80
cisco/ip_phone_7811_firmware
< 12.6\(1\)mn80
cisco/ip_phone_7821_firmware
< 12.6\(1\)mn80
cisco/ip_phone_7841_firmware
< 12.6\(1\)mn80
cisco/ip_phone_7861_firmware
< 12.6\(1\)mn80
cisco/ip_phone_8800_firmware
< 12.6\(1\)mn80
cisco/ip_phone_8811_firmware
< 12.6\(1\)mn80
cisco/ip_phone_8841_firmware
< 12.6\(1\)mn80
... and 4 more
Published
Feb 21, 2019
Tracked Since
Feb 18, 2026