MEDIUM · 6.5

CVE-2023-20047

A vulnerability in the Link Layer Discovery Protocol (LLDP) feature of Cisco Webex Room Phone and Cisco Webex Share devices could allow an unauthenticated, adjacent attacker to cause a denial of servi...

Vulnerability Description

A vulnerability in the Link Layer Discovery Protocol (LLDP) feature of Cisco Webex Room Phone and Cisco Webex Share devices could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to insufficient resource allocation. An attacker could exploit this vulnerability by sending crafted LLDP traffic to an affected device. A successful exploit could allow the attacker to exhaust the memory resources of the affected device, resulting in a crash of the LLDP process. If the affected device is configured to support LLDP only, this could cause an interruption to inbound and outbound calling. By default, these devices are configured to support both Cisco Discovery Protocol and LLDP. To recover operational state, the affected device needs a manual restart.

CVSS Score

6.5

MEDIUM

CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Attack Vector
ADJACENT_NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
NONE
Integrity
NONE
Availability
HIGH

Affected Products

VendorProductVersions
CiscoWebex Room Phone Firmware<= 1.2.0
CiscoWebex Room Phone-
CiscoWebex Share Firmware<= 1.2.0
CiscoWebex Share-
CiscoSip Ip Phone Software<= 1.2.0

Related Weaknesses (CWE)

References

FAQ

What is CVE-2023-20047?

CVE-2023-20047 is a vulnerability with a CVSS score of 6.5 (MEDIUM). A vulnerability in the Link Layer Discovery Protocol (LLDP) feature of Cisco Webex Room Phone and Cisco Webex Share devices could allow an unauthenticated, adjacent attacker to cause a denial of servi...

How severe is CVE-2023-20047?

CVE-2023-20047 has been rated MEDIUM with a CVSS base score of 6.5/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2023-20047?

Check the references section above for vendor advisories and patch information. Affected products include: Cisco Webex Room Phone Firmware, Cisco Webex Room Phone, Cisco Webex Share Firmware, Cisco Webex Share, Cisco Sip Ip Phone Software.