LiveActive security incident?Get immediate response
CVE Record

CVE-2021-1379: Cisco IP Phones Cisco Discovery Protocol and Link Layer Discovery Protocol Remote Code Execution and Denial of Service Vulnerabilities

Multiple vulnerabilities in the Cisco Discovery Protocol and Link Layer Discovery Protocol (LLDP) implementations for Cisco IP Phone Series 68xx/78xx/88xx could allow an unauthenticated, adjacent attacker to execute code remotely or cause a reload of an affected IP phone. These vulnerabilities are due to missing checks when the IP phone processes a Cisco Discovery Protocol or LLDP packet. An attacker could exploit these vulnerabilities by sending a malicious Cisco Discovery Protocol or LLDP packet to the targeted IP phone. A successful exploit could allow the attacker to execute code on the affected IP phone or cause it to reload unexpectedly, resulting in a denial of service (DoS) condition.Note: Cisco Discovery Protocol is a Layer 2 protocol. To exploit these vulnerabilities, an attacker must be in the same broadcast domain as the affected device (Layer 2 adjacent).Cisco has released software updates that address these vulnerabilities. There are no workarounds that address these vulnerabilities.

MediumCVSS 6.5Not KEV-listedUpdated
Glexia's TakeAutomated analysismoderate

Security readout for executives and security teams

Plain-English summary

This issue affects certain Cisco IP phones. An attacker already on the same local network segment could send malicious discovery-protocol traffic that may crash a phone or execute code on it. It is not internet-routable, but it matters for offices where VoIP networks are reachable by untrusted devices.

Executive priority

Treat as a moderate internal-network risk. Prioritize sites where IP phones share local network access with unmanaged devices, guest ports, or weak segmentation. Patch through normal change control, with higher urgency for sensitive offices or exposed voice VLANs.

Technical view

CVE-2021-1379 is caused by missing checks in Cisco Discovery Protocol and LLDP packet handling on affected Cisco IP Phone Series 68xx/78xx/88xx software. It is unauthenticated but Layer 2 adjacent, scored CVSS 3.1 6.5, and mapped to CWE-120. Cisco released software updates and states there are no workarounds.

Likely exposure

Exposure is most likely in environments running affected Cisco IP phone firmware on shared VoIP VLANs or broadcast domains. Risk increases where visitor, workstation, or contractor devices can reach the same Layer 2 segment as phones.

Exploitation context

The provided sources do not show active exploitation, and the CVE is not marked KEV. Exploitation requires Layer 2 adjacency to the target phone, limiting reach compared with internet-facing vulnerabilities but still relevant for internal network compromise scenarios.

Researcher notes

Evidence supports adjacent unauthenticated RCE or DoS through CDP/LLDP parsing defects. The bundle does not provide exploit details, observed exploitation, or workaround options. Validation should focus on firmware matching, Layer 2 placement, and whether untrusted devices can send discovery traffic to phones.

Mitigation direction

  • Apply Cisco software updates for affected IP phone models and firmware trains.
  • Check Cisco guidance for exact fixed versions before scheduling upgrades.
  • Segment voice networks from user and guest access where operationally feasible.
  • Review switch controls that limit unauthorized devices on VoIP broadcast domains.

Validation and detection

  • Inventory Cisco IP phones and record model, firmware, and software train.
  • Compare deployed versions with Cisco affected-version guidance.
  • Confirm phones are not reachable from untrusted Layer 2 segments.
  • Document upgrade status and any devices awaiting vendor-supported remediation.
Prepared
Confidence
high
Sources
3

Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.

Potential ATT&CK relevance

Conservative CVE-to-ATT&CK context

These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.

ATT&CK lookup starting points

Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.

cwe · low confidence lookup

CWE-120: Exact CWE lookup

Use the exact CWE identifier as the starting point before reviewing related ATT&CK behavior. Open the exact CWE lookup page first, then review the ATT&CK searches from that MITRE weakness context. This is a Glexia lookup hint, not an official ATT&CK mapping.

Open ATT&CK lookup
description · low confidence lookup

Execution behavior lookup

The CVE wording references code or command execution, so execution technique review may help defensive triage. This is a Glexia inferred lookup path, not an official MITRE, ATT&CK, or CVE Program mapping.

Open ATT&CK lookup
cve · low confidence lookup

CVE-2021-1379 mapping review

Open the CVE-to-ATT&CK bridge for reviewed, inferred, or future official mappings tied to this CVE.

Open ATT&CK lookup
Vulnerability profileCVE Program record
Severity
Medium
CVSS
6.5 (3.1)
Known Exploited
No
Published

Vector: CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/RL:X/RC:X/E:X

Official CVE source material

CNA and ADP enrichment extracted from CVE v5

These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.

1CVSS vectors
0Timeline events
0ADP providers
3Source links

CVSS vector scores

1 official score

We collect every scored CVSS vector available in the official CNA and ADP containers. When more than one version is present, the table keeps the source vectors side by side instead of collapsing them into the highest score.

ScoreVersionSeverityVectorExploitImpactSource
6.5CVSS 3.1MediumCVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/RL:X/RC:X/E:X2.83.6Primary CVE score

Vulnerability scoring details

Base CVSS 3.1 score

6.5Medium
CVSS 3.1 vector shape for CVE-2021-1379Attack VectorAttack ComplexityPrivileges RequiredUser InteractionScopeConfidentiality ImpactIntegrity ImpactAvailability Impact

Vector: CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/RL:X/RC:X/E:X

Attack Vector
NetworkAdjacentLocalPhysical
Attack Complexity
LowHigh
Privileges Required
NoneLowHigh
User Interaction
NoneRequired
Scope
ChangedUnchanged
Confidentiality Impact
HighLowNone
Integrity Impact
HighLowNone
Availability Impact
HighLowNone
Affected products

Products and packages named in the record

VendorProductVersion / packageStatus
CiscoCisco IP Phones with Multiplatform Firmware11.1.2, 11.2.1, 11.2.3, 11.2.2, 11.2.3 MSR1-1, 11.1.2 MSR1-1, 11.1.1, 11.1.2 MSR3-1, 11.0.0, 11.1.1 MSR1-1, 11.0.1, 11.1.1 MSR2-1, 11.2.4, 11.0.1 MSR1-1, 11.0.2, 11.3.1, 11.3.1 MSR1-3, 11.3.2, 11.3.1 MSR2-6, 11.3.1 MSR3-3unknown
CiscoCisco Session Initiation Protocol (SIP) Software9.0(3), 9.0(2)SR2, 9.0(2)SR1, 9.2(1), 9.4(2)SR1, 9.4(2), 9.4(2)SR2, 9.4(2)SR3, 9.3(1)SR2, 9.3(1)SR3, 9.3(1)SR1, 9.1(1)SR1, 9.3(1)SR4, 9.2(3), 9.2(1)SR2, 9.3(1), 9.4(2)SR4, 12.1(1)SR1, 11.5(1), 10.3(2), 10.2(2), 10.3(1), 10.3(1)SR4, 11.0(1), 10.4(1)SR2 3rd Party, 11.7(1), 12.1(1), 11.0(0.7) MPP, 9.3(4) 3rd Party, 12.5(1)SR2, 10.2(1)SR1, 9.3(4)SR3 3rd Party, 10.2(1), 12.5(1), 10.3(1)SR2, 11-0-1MSR1-1, 10.4(1) 3rd Party, 12.5(1)SR1, 11.5(1)SR1, 10.1(1)SR2, 12.0(1)SR2, 12.6(1), 10.3(1.11) 3rd Party, 12.0(1), 12.0(1)SR1, 9.3(3), 12.5(1)SR3, 10.3(1)SR4b, 9.3(4)SR1 3rd Party, 10.3(1)SR5, 10.1(1.9), 10.3(1.9) 3rd Party, 9.3(4)SR2 3rd Party, 10.3(1)SR1, 10.3(1)SR3, 10.1(1)SR1, 12.0(1)SR3, 12.6(1)SR1, 12.7(1), 10.3(1)SR6, 12.8(1), 12.7(1)SR1, 11.0(2)SR1, 11.0(4), 11.0(2), 11.0(4)SR3, 11.0(5), 11.0(3)SR2, 11.0(3)SR4, 11.0(3)SR3, 11.0(2)SR2, 11.0(4)SR1, 11.0(5)SR3, 11.0(3), 11.0(5)SR2, 11.0(3)SR6, 11.0(5)SR1, 11.0(4)SR2, 11.0(3)SR1, 11.0(3)SR5unknown
CiscoCisco Small Business IP Phones7.4.8, 7.4.3, 7.5.5a, 7.3.7, 7.5.2, 7.5.1, 7.4.6, 7.5.7, 7.4.4, 7.6.2SR3, 7.6.2, 7.5.6, 7.5.6c, 7.6.0, 7.4.7, 7.6.2SR6, 7.5.2b, 7.5.5, 7.5.6a, 7.6.2SR2, 7.5.3, 7.5.2a, 7.5.6(XU), 7.5.7s, 7.6.2SR4, 7.6.2SR1, 7.4.9, 7.5.5b, 7.6.2SR5, 7.5.4, 7.6.1, 7.6.2SR7unknown
Weakness

CWE details

CWE links open Glexia weakness intelligence pages with official CWE context, developer remediation guidance, and related CVE mappings.

CWE-120 · source CWE mapping

Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')

Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') represents a recurring weakness pattern that can create exploitable paths when design, validation, or implementation controls are missing.