CVE-2020-3574
Summary
| CVE | CVE-2020-3574 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2020-11-06 19:15:00 UTC |
| Updated | 2023-11-07 03:22:00 UTC |
| Description | A vulnerability in the TCP packet processing functionality of Cisco IP Phones could allow an unauthenticated, remote attacker to cause the phone to stop responding to incoming calls, drop connected calls, or unexpectedly reload. The vulnerability is due to insufficient TCP ingress packet rate limiting. An attacker could exploit this vulnerability by sending a high and sustained rate of crafted TCP traffic to the targeted device. A successful exploit could allow the attacker to impact operations of the phone or cause the phone to reload, leading to a denial of service (DoS) condition. |
Risk And Classification
Problem Types: NVD-CWE-Other
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Hardware | Cisco | Ip Dect 210 | - | All | All | All |
| Hardware | Cisco | Ip Dect 210 | - | All | All | All |
| Operating System | Cisco | Ip Dect 210 Firmware | All | All | All | All |
| Operating System | Cisco | Ip Dect 210 Firmware | All | All | All | All |
| Hardware | Cisco | Ip Dect 6825 | - | All | All | All |
| Hardware | Cisco | Ip Dect 6825 | - | All | All | All |
| Operating System | Cisco | Ip Dect 6825 Firmware | All | All | All | All |
| Operating System | Cisco | Ip Dect 6825 Firmware | All | All | All | All |
| Hardware | Cisco | Ip Phone 8811 | - | All | All | All |
| Hardware | Cisco | Ip Phone 8811 | - | All | All | All |
| Operating System | Cisco | Ip Phone 8811 Firmware | All | All | All | All |
| Operating System | Cisco | Ip Phone 8811 Firmware | All | All | All | All |
| Hardware | Cisco | Ip Phone 8841 | - | All | All | All |
| Hardware | Cisco | Ip Phone 8841 | - | All | All | All |
| Operating System | Cisco | Ip Phone 8841 Firmware | All | All | All | All |
| Operating System | Cisco | Ip Phone 8841 Firmware | All | All | All | All |
| Hardware | Cisco | Ip Phone 8851 | - | All | All | All |
| Hardware | Cisco | Ip Phone 8851 | - | All | All | All |
| Operating System | Cisco | Ip Phone 8851 Firmware | All | All | All | All |
| Operating System | Cisco | Ip Phone 8851 Firmware | All | All | All | All |
| Hardware | Cisco | Ip Phone 8861 | - | All | All | All |
| Hardware | Cisco | Ip Phone 8861 | - | All | All | All |
| Operating System | Cisco | Ip Phone 8861 Firmware | All | All | All | All |
| Operating System | Cisco | Ip Phone 8861 Firmware | All | All | All | All |
| Hardware | Cisco | Unified Ip Conference Phone 8831 | - | All | All | All |
| Hardware | Cisco | Unified Ip Conference Phone 8831 | - | All | All | All |
| Operating System | Cisco | Unified Ip Conference Phone 8831 Firmware | 9.3\(4\) | servicerelease3 | All | All |
| Operating System | Cisco | Unified Ip Conference Phone 8831 Firmware | 9.3\(4\) | servicerelease3 | All | All |
| Hardware | Cisco | Webex Room Phone | - | All | All | All |
| Hardware | Cisco | Webex Room Phone | - | All | All | All |
| Operating System | Cisco | Webex Room Phone Firmware | All | All | All | All |
| Operating System | Cisco | Webex Room Phone Firmware | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Cisco IP Phone TCP Packet Flood Denial of Service Vulnerability | CISCO | tools.cisco.com | Patch, Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.