Cisco reveals zero-day vulnerability in IP phones
Cisco has disclosed a high-severity zero-day vulnerability affecting the latest generation of its IP phones and exposing them to remote code execution and denial of service attacks. The affected devices include Cisco IP phones running 7800 and 8800 Series firmware version 14.2 and earlier.
The company alerted that its Product Security Incident Response Team (PSIRT) is aware that proof-of-concept exploit code is available and that the vulnerability has been publicly discussed. The security flaw is caused by insufficient input validation of received Cisco Discovery Protocol packets, which is exploited by unauthenticated and adjacent attackers to trigger a stack overflow.
Cisco has not released security updates to address this bug before disclosure and says that a patch will be available in January 2023. However, Cisco provides mitigation advice for admins who want to secure vulnerable devices in their environment from potential attacks.
Cisco warned that customers should not deploy any workarounds or mitigations before first evaluating the applicability to their own environment and any impact to such environment.
See What’s Next in Tech With the Fast Forward Newsletter
Tweets From @varindiamag
Nothing to see here - yet
When they Tweet, their Tweets will show up here.