PT-2021-4907 · Cisco · Cisco Small Business 220 Series Smart Switches

Qian Chen

·

Published

2021-10-06

·

Updated

2021-11-06

·

CVE-2021-34778

CVSS v3.1

4.3

Medium

VectorAV:A/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions Cisco Small Business 220 Series Smart Switches (affected versions not specified)
Description The issue is related to a buffer overflow vulnerability in the Link Layer Discovery Protocol (LLDP) implementation. An unauthenticated, adjacent attacker could execute code on the affected device, cause it to reload unexpectedly, or corrupt the LLDP database. To exploit this issue, an attacker must be in the same broadcast domain as the affected device.
Recommendations For Cisco Small Business 220 Series Smart Switches, update to the latest firmware version that addresses these vulnerabilities. At the moment, there is no information about specific steps for other potentially affected versions.

Fix

Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2021-05642
BDU:2021-05709
CVE-2021-34778

Affected Products

Cisco Small Business 220 Series Smart Switches