7.4

CVE-2021-1308

Multiple vulnerabilities exist in the Link Layer Discovery Protocol (LLDP) implementation for Cisco Small Business RV Series Routers. An unauthenticated, adjacent attacker could execute arbitrary code or cause an affected router to leak system memory or reload. A memory leak or device reload would cause a denial of service (DoS) condition on an affected device. For more information about these vulnerabilities, see the Details section of this advisory. Note: LLDP is a Layer 2 protocol. To exploit these vulnerabilities, an attacker must be in the same broadcast domain as the affected device (Layer 2 adjacent).

Data is provided by the National Vulnerability Database (NVD)
CiscoRv132w Firmware Version1.0.0.14
   CiscoRv132w Version-
CiscoRv132w Firmware Version1.0.1.14
   CiscoRv132w Version-
CiscoRv132w Firmware Version1.0.1.20
   CiscoRv132w Version-
CiscoRv134w Firmware Version1.0.0.14
   CiscoRv134w Version-
CiscoRv134w Firmware Version1.0.1.14
   CiscoRv134w Version-
CiscoRv134w Firmware Version1.0.1.20
   CiscoRv134w Version-
CiscoRv160 Firmware Version1.0.0.14
   CiscoRv160 Version-
CiscoRv160 Firmware Version1.0.1.14
   CiscoRv160 Version-
CiscoRv160 Firmware Version1.0.1.20
   CiscoRv160 Version-
CiscoRv160w Firmware Version1.0.0.14
   CiscoRv160w Version-
CiscoRv160w Firmware Version1.0.1.14
   CiscoRv160w Version-
CiscoRv160w Firmware Version1.0.1.20
   CiscoRv160w Version-
CiscoRv260 Firmware Version1.0.0.14
   CiscoRv260 Version-
CiscoRv260 Firmware Version1.0.1.14
   CiscoRv260 Version-
CiscoRv260 Firmware Version1.0.1.20
   CiscoRv260 Version-
CiscoRv260p Firmware Version1.0.0.14
   CiscoRv260p Version-
CiscoRv260p Firmware Version1.0.1.14
   CiscoRv260p Version-
CiscoRv260p Firmware Version1.0.1.20
   CiscoRv260p Version-
CiscoRv260w Firmware Version1.0.0.14
   CiscoRv260w Version-
CiscoRv260w Firmware Version1.0.1.14
   CiscoRv260w Version-
CiscoRv260w Firmware Version1.0.1.20
   CiscoRv260w Version-
CiscoRv340 Firmware Version1.0.0.14
   CiscoRv340 Version-
CiscoRv340 Firmware Version1.0.1.14
   CiscoRv340 Version-
CiscoRv340 Firmware Version1.0.1.20
   CiscoRv340 Version-
CiscoRv340w Firmware Version1.0.0.14
   CiscoRv340w Version-
CiscoRv340w Firmware Version1.0.1.14
   CiscoRv340w Version-
CiscoRv340w Firmware Version1.0.1.20
   CiscoRv340w Version-
CiscoRv345 Firmware Version1.0.0.14
   CiscoRv345 Version-
CiscoRv345 Firmware Version1.0.1.14
   CiscoRv345 Version-
CiscoRv345 Firmware Version1.0.1.20
   CiscoRv345 Version-
CiscoRv345p Firmware Version1.0.0.14
   CiscoRv345p Version-
CiscoRv345p Firmware Version1.0.1.14
   CiscoRv345p Version-
CiscoRv345p Firmware Version1.0.1.20
   CiscoRv345p Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.1% 0.242
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 7.4 2.8 4
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H
nvd@nist.gov 6.1 6.5 6.9
AV:A/AC:L/Au:N/C:N/I:N/A:C
psirt@cisco.com 7.4 2.8 4
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H
CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer

The product performs operations on a memory buffer, but it reads from or writes to a memory location outside the buffer's intended boundary. This may result in read or write operations on unexpected memory locations that could be linked to other variables, data structures, or internal program data.

CWE-401 Missing Release of Memory after Effective Lifetime

The product does not sufficiently track and release allocated memory after it has been used, which slowly consumes remaining memory.