VDB

CVE-2022-20766

CVE-2022-20766 PUBLISHED CVSS 5.300000190734863 MEDIUM

A vulnerability in the Cisco Discovery Protocol functionality of Cisco ATA 190 Series Adaptive Telephone Adapter firmware could allow an unauthenticated, remote attacker to cause a DoS condition on an affected device. This vulnerability is due to an out-of-bounds read when processing Cisco Discovery Protocol packets. An attacker could exploit this vulnerability by sending crafted Cisco Discovery Protocol packets to an affected device. A successful exploit could allow the attacker to cause a service restart.Cisco has released firmware updates that address this vulnerability. There are no workarounds that address this vulnerability.

EPSS 0.86% · 57.1th percentile

Risk Scores

CVSS 3.1
5.300000190734863
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
EPSS Score
0.86%
57.1th percentile

Affected Products

VendorProductVersions
CiscoCisco Analog Telephone Adaptor (ATA) Software*, *, 2.16(2)
ciscoata_190_firmware0

Timeline

  • Oct 5, 2022 CVE Published
  • Nov 15, 2024 PoC Published
  • Nov 16, 2024 EPSS Score
  • Dec 5, 2024 EPSS Score
  • Dec 23, 2024 EPSS Score
  • Jan 11, 2025 EPSS Score
  • Jan 29, 2025 EPSS Score
  • Feb 16, 2025 EPSS Score
  • Mar 6, 2025 EPSS Score
  • Mar 24, 2025 EPSS Score
  • Apr 12, 2025 EPSS Score
  • Apr 30, 2025 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›