Multiple vulnerabilities were identified in Cisco products, a remote attacker could exploit some of these vulnerabilities to trigger denial of service condition and remote code execution on the targeted system.
A vulnerability in the Cisco Discovery Protocol implementation for Cisco IP Phone, Cisco IOS XR Software and Cisco NX-OS Software could allow an unauthenticated, adjacent attacker to remotely execute code with root privileges or cause a reload of an affected device.
The vulnerability exists because the Cisco Discovery Protocol parser does not properly validate input for certain fields in a Cisco Discovery Protocol message. An attacker could exploit this vulnerability by sending a malicious Cisco Discovery Protocol packet to an affected device. An successful exploit could allow the attacker to cause a stack overflow, which could allow the attacker to execute arbitrary code with administrative privileges on an affected device.
Affected Products:
- Cisco IP phones with Cisco Discovery Protocol enabled and running a vulnerable firmware release
- Cisco IOS XR Software (32-bit or 64-bit) with Cisco Discovery Protocol enabled both globally and on at least one interface and if they are running a vulnerable release
- Cisco NX-OS Software with Cisco Discovery Protocol enabled both globally and on at least one interface and if they are running a vulnerable release
- Cisco NX-OS Software with Cisco Discovery Protocol enabled both globally and on at least one interface and if they are running a vulnerable release
For further information please refer to the links below:
NX-OS https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20200205-nxos-cdp-rce
Matsco recommends any affected systems are updated as soon as convenient.