PT-2021-3495 · Cisco · Cisco Video Surveillance 7000 Series Ip Cameras

Qian Chen

·

Published

2021-06-04

·

Updated

2022-08-05

·

CVE-2021-1563

CVSS v3.1

6.5

Medium

VectorAV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Cisco Video Surveillance 7000 Series IP Cameras (affected versions not specified)
Description The issue is related to the implementation of the Cisco Discovery Protocol and Link Layer Discovery Protocol (LLDP) in the Cisco Video Surveillance 7000 Series IP Cameras, which could allow an unauthenticated, adjacent attacker to cause a memory leak. This could lead to a denial of service (DoS) condition on an affected device. The vulnerabilities are due to incorrect processing of certain Cisco Discovery Protocol and LLDP packets at ingress time. An attacker could exploit these vulnerabilities by sending crafted Cisco Discovery Protocol or LLDP packets to an affected device, causing the device to continuously consume memory, which could cause the device to crash and reload. Note that to exploit these vulnerabilities, an attacker must be in the same broadcast domain as the affected device (Layer 2 adjacent).
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Resource Exhaustion

Memory Leak

Weakness Enumeration

Related Identifiers

BDU:2021-03525
CVE-2021-1563

Affected Products

Cisco Video Surveillance 7000 Series Ip Cameras