cbcvebase.
CVE-2023-41910
published 2023-09-05

CVE-2023-41910: An issue was discovered in lldpd before 1.0.17. By crafting a CDP PDU packet with specific CDP_TLV_ADDRESSES TLVs, a malicious actor can remotely force the…

PriorityP342critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
0.95%
57.4th percentile
An issue was discovered in lldpd before 1.0.17. By crafting a CDP PDU packet with specific CDP_TLV_ADDRESSES TLVs, a malicious actor can remotely force the lldpd daemon to perform an out-of-bounds read on heap memory. This occurs in cdp_decode in daemon/protocols/cdp.c.

Affected

7 ranges
VendorProductVersion rangeFixed in
debianlldpd< lldpd 1.0.16-1+deb12u1 (bookworm)lldpd 1.0.16-1+deb12u1 (bookworm)
lldpd_projectlldpd< 1.0.171.0.17
lldpd_projectlldpd>= 0 < 1.0.11-1+deb11u21.0.11-1+deb11u2
lldpd_projectlldpd>= 0 < 1.0.16-1+deb12u11.0.16-1+deb12u1
lldpd_projectlldpd>= 0 < 1.0.17-11.0.17-1
lldpd_projectlldpd>= 0 < 1.0.17-11.0.17-1
msrccbl2_lldpd_1.0.14-3_on_cbl_mariner_2.0

CVSS provenance

nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
osv9.8CRITICAL
vendor_debian9.8CRITICAL
vendor_msrc9.8CRITICAL
vendor_redhat9.8CRITICAL
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.