PT-2021-4741 · Cisco · Cisco Ios Xe+1

Published

2021-09-22

·

Updated

2023-05-22

·

CVE-2021-34703

CVSS v2.0

6.8

Medium

VectorAV:N/AC:L/Au:S/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions Cisco IOS Software (affected versions not specified) Cisco IOS XE Software (affected versions not specified)
Description A vulnerability in the Link Layer Discovery Protocol (LLDP) message parser could allow an attacker to trigger a reload of an affected device, resulting in a denial of service (DoS) condition. This vulnerability is due to improper initialization of a buffer. An attacker could exploit this vulnerability via any of the following methods: An authenticated, remote attacker could access the LLDP neighbor table via either the CLI or SNMP while the device is in a specific state. An unauthenticated, adjacent attacker could corrupt the LLDP neighbor table by injecting specific LLDP frames into the network and then waiting for an administrator of the device or a network management system (NMS) managing the device to retrieve the LLDP neighbor table of the device via either the CLI or SNMP. An authenticated, adjacent attacker with SNMP read-only credentials or low privileges on the device CLI could corrupt the LLDP neighbor table by injecting specific LLDP frames into the network and then accessing the LLDP neighbor table via either the CLI or SNMP.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

DoS

Improper Initialization

Weakness Enumeration

Related Identifiers

BDU:2021-05450
CVE-2021-34703

Affected Products

Cisco Ios
Cisco Ios Xe