Cisco has disclosed a high - severity vulnerability that leaves the latest generation of IP phones exposed to remote code execution and denial of service (DoS) attacks.

Cisco is a leading provider of networking technologies and solutions. It is one of the most recognized names in the industry, offering a wide range of products and services that meet the needs of businesses around the world.
See also: Zombinder: New service injects malware into legitimate applications
On Thursday, however, the company revealed that Product Security Incident Response Team (PSIRT) is aware that there is code available that shows how the vulnerability can be exploited.
However, Cisco researchers clarified that they have not observed or learned of any attempts to exploit this vulnerability in attacks.
Cisco has not yet released security updates to address this bug, but says a patch will be available in January 2023.
The vulnerability has been named CVE-2022-20968 and is caused by insufficient input validation of received Cisco Discovery Protocol packets, which can be exploited by unauthorized attackers to cause a stack overflow that can lead to remote code execution or a denial of service attack.
See also: How a dog photo exposed drug traffickers?
Devices affected by the vulnerability include Cisco IP phones with firmware 7800 and 8800 Series, version 14.2 and earlier.
Cisco was notified of the vulnerability by Qian Chen of the Codesafe Team of Legendsec at QI-ANXIN Group.

Temporary solution for vulnerable Cisco IP Phones
As we said above, there is no security to address the CVE-2022-20968 vulnerability, but Cisco is providing mitigation advice for administrators who want to take steps to protect vulnerable IP phones in their environment.
This requires disabling the Cisco Discovery Protocol on affected 7800 and 8800 Series IP phones that also support the Link Layer Discovery Protocol (LLDP).
“Devices , will then use LLDP to discover configuration dataand so on,” Cisco explained on Thursday.
See also: CloudSEK: Claims to have been hacked by cybersecurity company
“This is not an insignificant change and will require work on the part of the business to assess any potential impacts to devices and implement the best approach to deploying this change to the business.”
It is recommended that administrators who want to deploy this threat mitigation method test its effectiveness and applicability for their environment.
Cisco warned that “customers should not implement solutions or mitigations before evaluating the applicability to their own environment and the potential impact.”
Source: www.bleepingcomputer.com
