CVE-2021-1308
published 2021-04-08CVE-2021-1308: Multiple vulnerabilities exist in the Link Layer Discovery Protocol (LLDP) implementation for Cisco Small Business RV Series Routers. An unauthenticated…
PriorityP336high7.4CVSS 3.1
AVAACLPRNUINSCCNINAH
EPSS
0.43%
35.4th percentile
Multiple vulnerabilities exist in the Link Layer Discovery Protocol (LLDP) implementation for Cisco Small Business RV Series Routers. An unauthenticated, adjacent attacker could execute arbitrary code or cause an affected router to leak system memory or reload. A memory leak or device reload would cause a denial of service (DoS) condition on an affected device. For more information about these vulnerabilities, see the Details section of this advisory. Note: LLDP is a Layer 2 protocol. To exploit these vulnerabilities, an attacker must be in the same broadcast domain as the affected device (Layer 2 adjacent).
Affected
36 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | cisco_small_business_rv_series_router_firmware | — | — |
| cisco | rv132w_firmware | — | — |
| cisco | rv132w_firmware | — | — |
| cisco | rv132w_firmware | — | — |
| cisco | rv134w_firmware | — | — |
| cisco | rv134w_firmware | — | — |
| cisco | rv134w_firmware | — | — |
| cisco | rv160_firmware | — | — |
| cisco | rv160_firmware | — | — |
| cisco | rv160_firmware | — | — |
| cisco | rv160w_firmware | — | — |
| cisco | rv160w_firmware | — | — |
| cisco | rv160w_firmware | — | — |
| cisco | rv260_firmware | — | — |
| cisco | rv260_firmware | — | — |
| cisco | rv260_firmware | — | — |
| cisco | rv260p_firmware | — | — |
| cisco | rv260p_firmware | — | — |
| cisco | rv260p_firmware | — | — |
| cisco | rv260w_firmware | — | — |
| cisco | rv260w_firmware | — | — |
| cisco | rv260w_firmware | — | — |
| cisco | rv340_firmware | — | — |
| cisco | rv340_firmware | — | — |
| cisco | rv340_firmware | — | — |
CVSS provenance
nvdv3.17.4HIGHCVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H
nvdv2.06.1MEDIUMAV:A/AC:L/Au:N/C:N/I:N/A:C
vendor_cisco8.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Chrome
Stable Channel Update for Desktop: CVE-2022-1308
vendor_chrome·2022-04-11·CVSS 8.8
CVE-2022-1308 [HIGH] Stable Channel Update for Desktop: CVE-2022-1308
Stable Channel Update for Desktop
CVE-2022-1308: Use after free in BFCache. Reported by Samet Bekmezci @sametbekmezci on 2021-12-28 [$TBD][ 1106456 ] High CVE-2022-1309: Insufficient policy enforcement in developer tools
Reported by David Erceg on 2020-07-17 [$TBD][ 1307610 ] High CVE-2022-1310: Use after free in regular expressions
Severity: high
Cisco
Cisco Small Business RV Series Routers Link Layer Discovery Protocol Vulnerabilities
vendor_cisco·2021-04-07·CVSS 8.8
CVE-2021-1251 [HIGH] CWE-119 Cisco Small Business RV Series Routers Link Layer Discovery Protocol Vulnerabilities
Cisco Small Business RV Series Routers Link Layer Discovery Protocol Vulnerabilities
Multiple vulnerabilities exist in the Link Layer Discovery Protocol (LLDP) implementation for Cisco Small Business RV Series Routers. An unauthenticated, adjacent attacker could execute arbitrary code or cause an affected router to leak system memory or reload. A memory leak or device reload would cause a denial of service (DoS) condition on an affected device.
For more information about these vulnerabilities, see the Details section of this advisory.
Note: LLDP is a Layer 2 protocol. To exploit these vulnerabilities, an attacker must be in the same broadcast domain as the affected device (Layer 2 adjacent).
Cisco has released software updates that address these vulnerabilities. There are no workarounds t
Cisco
Cisco Small Business RV Series Routers Link Layer Discovery Protocol Vulnerabilities
vendor_cisco·CVSS 3.1
CVE-2021-1308 Cisco Small Business RV Series Routers Link Layer Discovery Protocol Vulnerabilities
CVE-2021-1308: Cisco Small Business RV Series Routers Link Layer Discovery Protocol Vulnerabilities
Multiple vulnerabilities exist in the Link Layer Discovery Protocol (LLDP) implementation for Cisco Small Business RV Series Routers. An unauthenticated, adjacent attacker could execute arbitrary code or cause an affected router to leak system memory or reload. A memory leak or device reload would cause a denial of service (DoS) condition on an affected device. For more information about these vulnerabilities, see the
CVSS: 3.1
CWE: CWE-119, CWE-130, CWE-400, CWE-119, CWE-130, CWE-400
Bug IDs: CSCvw62392, CSCvw62395, CSCvw62410, CSCvw62392, CSCvw62395
GHSA
GHSA-jp7c-8h7v-c764: Multiple vulnerabilities exist in the Link Layer Discovery Protocol (LLDP) implementation for Cisco Small Business RV Series Routers
ghsa_unreviewed·2022-05-24
CVE-2021-1308 [HIGH] CWE-119 GHSA-jp7c-8h7v-c764: Multiple vulnerabilities exist in the Link Layer Discovery Protocol (LLDP) implementation for Cisco Small Business RV Series Routers
Multiple vulnerabilities exist in the Link Layer Discovery Protocol (LLDP) implementation for Cisco Small Business RV Series Routers. An unauthenticated, adjacent attacker could execute arbitrary code or cause an affected router to leak system memory or reload. A memory leak or device reload would cause a denial of service (DoS) condition on an affected device. For more information about these vulnerabilities, see the Details section of this advisory. Note: LLDP is a Layer 2 protocol. To exploit these vulnerabilities, an attacker must be in the same broadcast domain as the affected device (Layer 2 adjacent).
No detection rules found.
No public exploits indexed.
Talos
Vulnerability Spotlight: Memory corruption vulnerability in PowerISO’s DMG handler
blogs_talos·2021-06-28·CVSS 7.8
[HIGH] Vulnerability Spotlight: Memory corruption vulnerability in PowerISO’s DMG handler
## Vulnerability Spotlight: Memory corruption vulnerability in PowerISO’s DMG handler
Piotr Bania of Cisco Talos discovered this vulnerability. Blog by Jon Munshaw.
Cisco Talos recently discovered a memory corruption vulnerability in PowerISO’s handler that deals with DMG files.
PowerISO is a CD/DVD/BD image file processing tool, which allows users to open, extract, burn, create, edit, compress, encrypt, split and convert ISO files, and mount ISO files with an internal virtual drive. Recent versions provide support for Apple Disk Image file format, also known as DMG files. TALOS-2021-1308 (CVE-2021-21871) is a memory corruption vulnerability in PowerISO that could result in the attacker gaining the ability to execute code on the victim machine. An attacker can exploit this vulnerability
Talos
Vulnerability Spotlight: Memory corruption vulnerability in PowerISO’s DMG handler
blogs_talos·2021-06-28·CVSS 7.8
[HIGH] Vulnerability Spotlight: Memory corruption vulnerability in PowerISO’s DMG handler
Piotr Bania of Cisco Talos discovered this vulnerability. Blog by Jon Munshaw.
Cisco Talos recently discovered a memory corruption vulnerability in PowerISO’s handler that deals with DMG files.
PowerISO is a CD/DVD/BD image file processing tool, which allows users to open, extract, burn, create, edit, compress, encrypt, split and convert ISO files, and mount ISO files with an internal virtual drive. Recent versions provide support for Apple Disk Image file format, also known as DMG files. TALOS-2021-1308 (CVE-2021-21871) is a memory corruption vulnerability in PowerISO that could result in the attacker gaining the ability to execute code on the victim machine. An attacker can exploit this vulnerability by tricking a user into opening a specially crafted DMG file.
Cisco Talos worked with
2021-04-08
Published