PT-2021-4907 · Cisco · Cisco Small Business 220 Series Smart Switches
Qian Chen
·
Published
2021-10-06
·
Updated
2021-11-06
·
CVE-2021-34778
CVSS v3.1
4.3
Medium
| Vector | AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Cisco Small Business 220 Series Smart Switches (affected versions not specified)
Description
The issue is related to a buffer overflow vulnerability in the Link Layer Discovery Protocol (LLDP) implementation. An unauthenticated, adjacent attacker could execute code on the affected device, cause it to reload unexpectedly, or corrupt the LLDP database. To exploit this issue, an attacker must be in the same broadcast domain as the affected device.
Recommendations
For Cisco Small Business 220 Series Smart Switches, update to the latest firmware version that addresses these vulnerabilities.
At the moment, there is no information about specific steps for other potentially affected versions.
Fix
Buffer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Cisco Small Business 220 Series Smart Switches