CVE-2021-1309
published 2021-04-08CVE-2021-1309: Multiple vulnerabilities exist in the Link Layer Discovery Protocol (LLDP) implementation for Cisco Small Business RV Series Routers. An unauthenticated…
PriorityP348high8.8CVSS 3.1
AVAACLPRNUINSUCHIHAH
EPSS
0.52%
40.7th percentile
Multiple vulnerabilities exist in the Link Layer Discovery Protocol (LLDP) implementation for Cisco Small Business RV Series Routers. An unauthenticated, adjacent attacker could execute arbitrary code or cause an affected router to leak system memory or reload. A memory leak or device reload would cause a denial of service (DoS) condition on an affected device. For more information about these vulnerabilities, see the Details section of this advisory. Note: LLDP is a Layer 2 protocol. To exploit these vulnerabilities, an attacker must be in the same broadcast domain as the affected device (Layer 2 adjacent).
Affected
36 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | cisco_small_business_rv_series_router_firmware | — | — |
| cisco | rv132w_firmware | — | — |
| cisco | rv132w_firmware | — | — |
| cisco | rv132w_firmware | — | — |
| cisco | rv134w_firmware | — | — |
| cisco | rv134w_firmware | — | — |
| cisco | rv134w_firmware | — | — |
| cisco | rv160_firmware | — | — |
| cisco | rv160_firmware | — | — |
| cisco | rv160_firmware | — | — |
| cisco | rv160w_firmware | — | — |
| cisco | rv160w_firmware | — | — |
| cisco | rv160w_firmware | — | — |
| cisco | rv260_firmware | — | — |
| cisco | rv260_firmware | — | — |
| cisco | rv260_firmware | — | — |
| cisco | rv260p_firmware | — | — |
| cisco | rv260p_firmware | — | — |
| cisco | rv260p_firmware | — | — |
| cisco | rv260w_firmware | — | — |
| cisco | rv260w_firmware | — | — |
| cisco | rv260w_firmware | — | — |
| cisco | rv340_firmware | — | — |
| cisco | rv340_firmware | — | — |
| cisco | rv340_firmware | — | — |
CVSS provenance
nvdv3.18.8HIGHCVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.08.3HIGHAV:A/AC:L/Au:N/C:C/I:C/A:C
vendor_cisco8.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Chrome
Stable Channel Update for Desktop: CVE-2022-1308
vendor_chrome·2022-04-11·CVSS 8.8
CVE-2022-1308 [HIGH] Stable Channel Update for Desktop: CVE-2022-1308
Stable Channel Update for Desktop
CVE-2022-1308: Use after free in BFCache. Reported by Samet Bekmezci @sametbekmezci on 2021-12-28 [$TBD][ 1106456 ] High CVE-2022-1309: Insufficient policy enforcement in developer tools
Reported by David Erceg on 2020-07-17 [$TBD][ 1307610 ] High CVE-2022-1310: Use after free in regular expressions
Severity: high
Cisco
Cisco Small Business RV Series Routers Link Layer Discovery Protocol Vulnerabilities
vendor_cisco·2021-04-07·CVSS 8.8
CVE-2021-1251 [HIGH] CWE-119 Cisco Small Business RV Series Routers Link Layer Discovery Protocol Vulnerabilities
Cisco Small Business RV Series Routers Link Layer Discovery Protocol Vulnerabilities
Multiple vulnerabilities exist in the Link Layer Discovery Protocol (LLDP) implementation for Cisco Small Business RV Series Routers. An unauthenticated, adjacent attacker could execute arbitrary code or cause an affected router to leak system memory or reload. A memory leak or device reload would cause a denial of service (DoS) condition on an affected device.
For more information about these vulnerabilities, see the Details section of this advisory.
Note: LLDP is a Layer 2 protocol. To exploit these vulnerabilities, an attacker must be in the same broadcast domain as the affected device (Layer 2 adjacent).
Cisco has released software updates that address these vulnerabilities. There are no workarounds t
Cisco
Cisco Small Business RV Series Routers Link Layer Discovery Protocol Vulnerabilities
vendor_cisco·CVSS 3.1
CVE-2021-1309 Cisco Small Business RV Series Routers Link Layer Discovery Protocol Vulnerabilities
CVE-2021-1309: Cisco Small Business RV Series Routers Link Layer Discovery Protocol Vulnerabilities
Multiple vulnerabilities exist in the Link Layer Discovery Protocol (LLDP) implementation for Cisco Small Business RV Series Routers. An unauthenticated, adjacent attacker could execute arbitrary code or cause an affected router to leak system memory or reload. A memory leak or device reload would cause a denial of service (DoS) condition on an affected device. For more information about these vulnerabilities, see the
CVSS: 3.1
CWE: CWE-119, CWE-130, CWE-400, CWE-119, CWE-130, CWE-400
Bug IDs: CSCvw62392, CSCvw62395, CSCvw62410, CSCvw62392, CSCvw62395
GHSA
GHSA-mqj7-w9r3-q3p2: Multiple vulnerabilities exist in the Link Layer Discovery Protocol (LLDP) implementation for Cisco Small Business RV Series Routers
ghsa_unreviewed·2022-05-24
CVE-2021-1309 [HIGH] CWE-119 GHSA-mqj7-w9r3-q3p2: Multiple vulnerabilities exist in the Link Layer Discovery Protocol (LLDP) implementation for Cisco Small Business RV Series Routers
Multiple vulnerabilities exist in the Link Layer Discovery Protocol (LLDP) implementation for Cisco Small Business RV Series Routers. An unauthenticated, adjacent attacker could execute arbitrary code or cause an affected router to leak system memory or reload. A memory leak or device reload would cause a denial of service (DoS) condition on an affected device. For more information about these vulnerabilities, see the Details section of this advisory. Note: LLDP is a Layer 2 protocol. To exploit these vulnerabilities, an attacker must be in the same broadcast domain as the affected device (Layer 2 adjacent).
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2021-04-08
Published