PT-2021-3498 · Cisco · Cisco Video Surveillance 7000 Series Ip Cameras

Qian Chen

·

Published

2021-07-07

·

Updated

2021-07-13

·

CVE-2021-1595

CVSS v3.1

6.5

Medium

VectorAV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Cisco Video Surveillance 7000 Series IP Cameras (affected versions not specified)
Description The issue is related to the Link Layer Discovery Protocol (LLDP) implementation, which could allow an unauthenticated, adjacent attacker to cause a memory leak. This is due to incorrect processing of certain LLDP packets at ingress time. An attacker could exploit this by sending crafted LLDP packets to an affected device, potentially causing the device to continuously consume memory, leading to a crash and reload, and resulting in a denial of service (DoS) condition. The attacker must be in the same broadcast domain as the affected device (Layer 2 adjacent) to exploit this issue.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Memory Leak

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2021-03528
CVE-2021-1595

Affected Products

Cisco Video Surveillance 7000 Series Ip Cameras