CVE-2021-1379

moderate-risk
Published 2024-11-18

Multiple vulnerabilities in the Cisco Discovery Protocol and Link Layer Discovery Protocol (LLDP) implementations for Cisco IP Phone Series 68xx/78xx/88xx could allow an unauthenticated, adjacent attacker to execute code remotely or cause a reload of an affected IP phone. These vulnerabilities are due to missing checks when the IP phone processes a Cisco Discovery Protocol or LLDP packet. An attacker could exploit these vulnerabilities by sending a malicious Cisco Discovery Protocol or LLDP packet to the targeted IP phone. A successful exploit could allow the attacker to execute code on the affected IP phone or cause it to reload unexpectedly, resulting in a denial of service (DoS) condition.Note: Cisco Discovery Protocol is a Layer 2 protocol. To exploit these vulnerabilities, an attacker must be in the same broadcast domain as the affected device (Layer 2 adjacent).Cisco has released software updates that address these vulnerabilities. There are no workarounds that address these vulnerabilities.

Do I need to act?

-
0.12% chance of exploitation
EPSS score — low exploit probability
-
Not on CISA KEV list
No confirmed active exploitation reported to CISA
?
Patch status unknown
Check vendor advisories for fix availability and mitigation guidance
6
CVSS 6.5/10 Medium
ADJACENT_NETWORK / LOW complexity

Affected Products (20)

Ip Conference Phone 7832 Firmware
Ip Conference Phone 7832 Firmware
Ip Conference Phone 7832 With Multiplatform Firmware
Ip Conference Phone 8832 Firmware
Ip Conference Phone 8832 Firmware
Ip Conference Phone 8832 With Multiplatform Firmware
Ip Phone 6821 With Multiplatform Firmware
Ip Phone 6841 With Multiplatform Firmware
Ip Phone 6851 With Multiplatform Firmware
Ip Phone 6861 With Multiplatform Firmware
Ip Phone 6871 With Multiplatform Firmware
Ip Phone 7811 Firmware
Ip Phone 7811 Firmware
Ip Phone 7811 With Multiplatform Firmware
Ip Phone 7821 Firmware
Ip Phone 7821 Firmware
Ip Phone 7821 With Multiplatform Firmware
Ip Phone 7841 Firmware
Ip Phone 7841 Firmware
Ip Phone 7841 With Multiplatform Firmware

Affected Vendors

48
/ 100
moderate-risk
Severity 21/34 · High
Exploitability 1/34 · Minimal
Exposure 26/34 · High