CVE-2019-1684

MEDIUM

Cisco IP Phone 7800/8800 < 12.6(1)MN80 - DoS via Cisco Discovery Protocol or LLDP

Title source: llm
STIX 2.1

Description

A vulnerability in the Cisco Discovery Protocol or Link Layer Discovery Protocol (LLDP) implementation for the Cisco IP Phone 7800 and 8800 Series could allow an unauthenticated, adjacent attacker to cause an affected phone to reload unexpectedly, resulting in a temporary denial of service (DoS) condition. The vulnerability is due to missing length validation of certain Cisco Discovery Protocol or LLDP packet header fields. An attacker could exploit this vulnerability by sending a malicious Cisco Discovery Protocol or LLDP packet to the targeted phone. A successful exploit could allow the attacker to cause the affected phone to reload unexpectedly, resulting in a temporary DoS condition. Versions prior to 12.6(1)MN80 are affected.

References (2)

Core 2
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/107104

Scores

CVSS v3 6.5
EPSS 0.0064
EPSS Percentile 46.1%
Attack Vector ADJACENT_NETWORK
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-119 CWE-399
Status published
Products (14)
cisco/ip_conference_phone_7832_firmware < 12.6\(1\)mn80
cisco/ip_conference_phone_8832_firmware < 12.6\(1\)mn80
cisco/ip_phone_7800_firmware < 12.6\(1\)mn80
cisco/ip_phone_7811_firmware < 12.6\(1\)mn80
cisco/ip_phone_7821_firmware < 12.6\(1\)mn80
cisco/ip_phone_7841_firmware < 12.6\(1\)mn80
cisco/ip_phone_7861_firmware < 12.6\(1\)mn80
cisco/ip_phone_8800_firmware < 12.6\(1\)mn80
cisco/ip_phone_8811_firmware < 12.6\(1\)mn80
cisco/ip_phone_8841_firmware < 12.6\(1\)mn80
... and 4 more
Published Feb 21, 2019
Tracked Since Feb 18, 2026