CVE-2021-1251
published 2021-04-08CVE-2021-1251: Multiple vulnerabilities exist in the Link Layer Discovery Protocol (LLDP) implementation for Cisco Small Business RV Series Routers. An unauthenticated…
PriorityP336high7.4CVSS 3.1
AVAACLPRNUINSCCNINAH
EPSS
0.43%
35.3th percentile
Multiple vulnerabilities exist in the Link Layer Discovery Protocol (LLDP) implementation for Cisco Small Business RV Series Routers. An unauthenticated, adjacent attacker could execute arbitrary code or cause an affected router to leak system memory or reload. A memory leak or device reload would cause a denial of service (DoS) condition on an affected device. For more information about these vulnerabilities, see the Details section of this advisory. Note: LLDP is a Layer 2 protocol. To exploit these vulnerabilities, an attacker must be in the same broadcast domain as the affected device (Layer 2 adjacent).
Affected
24 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | cisco_small_business_rv_series_router_firmware | — | — |
| cisco | rv132w_firmware | — | — |
| cisco | rv132w_firmware | — | — |
| cisco | rv134w_firmware | — | — |
| cisco | rv134w_firmware | — | — |
| cisco | rv160_firmware | — | — |
| cisco | rv160_firmware | — | — |
| cisco | rv160w_firmware | — | — |
| cisco | rv160w_firmware | — | — |
| cisco | rv260_firmware | — | — |
| cisco | rv260_firmware | — | — |
| cisco | rv260p_firmware | — | — |
| cisco | rv260p_firmware | — | — |
| cisco | rv260w_firmware | — | — |
| cisco | rv260w_firmware | — | — |
| cisco | rv340_firmware | — | — |
| cisco | rv340_firmware | — | — |
| cisco | rv340w_firmware | — | — |
| cisco | rv340w_firmware | — | — |
| cisco | rv345_firmware | — | — |
| cisco | rv345_firmware | — | — |
| cisco | rv345p_firmware | — | — |
| cisco | rv345p_firmware | — | — |
| cisco | small_business_rv_series_routers_link_layer_discovery_protocol | — | — |
CVSS provenance
nvdv3.17.4HIGHCVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H
nvdv2.06.1MEDIUMAV:A/AC:L/Au:N/C:N/I:N/A:C
vendor_cisco8.8HIGH
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Cisco
Cisco Small Business RV Series Routers Link Layer Discovery Protocol Vulnerabilities
vendor_cisco·2021-04-07·CVSS 8.8
CVE-2021-1251 [HIGH] CWE-119 Cisco Small Business RV Series Routers Link Layer Discovery Protocol Vulnerabilities
Cisco Small Business RV Series Routers Link Layer Discovery Protocol Vulnerabilities
Multiple vulnerabilities exist in the Link Layer Discovery Protocol (LLDP) implementation for Cisco Small Business RV Series Routers. An unauthenticated, adjacent attacker could execute arbitrary code or cause an affected router to leak system memory or reload. A memory leak or device reload would cause a denial of service (DoS) condition on an affected device.
For more information about these vulnerabilities, see the Details section of this advisory.
Note: LLDP is a Layer 2 protocol. To exploit these vulnerabilities, an attacker must be in the same broadcast domain as the affected device (Layer 2 adjacent).
Cisco has released software updates that address these vulnerabilities. There are no workarounds t
Cisco
Cisco Small Business RV Series Routers Link Layer Discovery Protocol Vulnerabilities
vendor_cisco·CVSS 3.1
CVE-2021-1251 Cisco Small Business RV Series Routers Link Layer Discovery Protocol Vulnerabilities
CVE-2021-1251: Cisco Small Business RV Series Routers Link Layer Discovery Protocol Vulnerabilities
Multiple vulnerabilities exist in the Link Layer Discovery Protocol (LLDP) implementation for Cisco Small Business RV Series Routers. An unauthenticated, adjacent attacker could execute arbitrary code or cause an affected router to leak system memory or reload. A memory leak or device reload would cause a denial of service (DoS) condition on an affected device. For more information about these vulnerabilities, see the
CVSS: 3.1
CWE: CWE-119, CWE-130, CWE-400, CWE-119, CWE-130, CWE-400
Bug IDs: CSCvw62392, CSCvw62395, CSCvw62410, CSCvw62392, CSCvw62395
GHSA
GHSA-8jq9-v6q2-frcj: Multiple vulnerabilities exist in the Link Layer Discovery Protocol (LLDP) implementation for Cisco Small Business RV Series Routers
ghsa_unreviewed·2022-05-24
CVE-2021-1251 [HIGH] CWE-119 GHSA-8jq9-v6q2-frcj: Multiple vulnerabilities exist in the Link Layer Discovery Protocol (LLDP) implementation for Cisco Small Business RV Series Routers
Multiple vulnerabilities exist in the Link Layer Discovery Protocol (LLDP) implementation for Cisco Small Business RV Series Routers. An unauthenticated, adjacent attacker could execute arbitrary code or cause an affected router to leak system memory or reload. A memory leak or device reload would cause a denial of service (DoS) condition on an affected device. For more information about these vulnerabilities, see the Details section of this advisory. Note: LLDP is a Layer 2 protocol. To exploit these vulnerabilities, an attacker must be in the same broadcast domain as the affected device (Layer 2 adjacent).
No detection rules found.
No public exploits indexed.
2021-04-08
Published