7.1
CVSSv2

CVE-2020-27827

Published: 18/03/2021 Updated: 26/11/2023
CVSS v2 Base Score: 7.1 | Impact Score: 6.9 | Exploitability Score: 8.6
CVSS v3 Base Score: 7.5 | Impact Score: 3.6 | Exploitability Score: 3.9
VMScore: 632
Vector: AV:N/AC:M/Au:N/C:N/I:N/A:C

Vulnerability Summary

A flaw was found in multiple versions of OpenvSwitch. Specially crafted LLDP packets can cause memory to be lost when allocating data to handle specific optional TLVs, potentially causing a denial of service. The highest threat from this vulnerability is to system availability.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

lldpd project lldpd

openvswitch openvswitch

redhat enterprise linux 7.0

redhat virtualization 4.0

redhat openstack 10

redhat enterprise linux 8.0

redhat openshift container platform 4.0

redhat openstack 13

fedoraproject fedora 33

siemens simatic_hmi_unified_comfort_panels_firmware

siemens simatic_net_cp_1243-1_firmware -

siemens simatic_net_cp_1243-8_irc_firmware -

siemens simatic_net_cp_1542sp-1_firmware -

siemens simatic_net_cp_1542sp-1_irc_firmware -

siemens simatic_net_cp_1543-1_firmware -

siemens simatic_net_cp_1543sp-1_firmware -

siemens simatic_net_cp_1545-1_firmware -

siemens tim_1531_irc_firmware

siemens sinumerik_one_firmware

Vendor Advisories

Synopsis Moderate: openvswitch213 security and bug fix update Type/Severity Security Advisory: Moderate Topic An update for openvswitch213 is now available for Fast Datapath for Red Hat Enterprise Linux 8Red Hat Product Security has rated this update as having a security impact of Moderate A Common Vuln ...
Debian Bug report logs - #980132 openvswitch: CVE-2020-27827 Package: src:openvswitch; Maintainer for src:openvswitch is Debian OpenStack <team+openstack@trackerdebianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Thu, 14 Jan 2021 21:42:01 UTC Severity: grave Tags: security, upstream Found in ve ...
Two vulnerabilities were discovered in the LLPD implementation of Open vSwitch, a software-based Ethernet virtual switch, which could result in denial of service For the stable distribution (buster), these problems have been fixed in version 2106+ds1-0+deb10u1 We recommend that you upgrade your openvswitch packages For the detailed security st ...
A security issue was found in lldpd before version 108 A packet that contains multiple instances of certain TLVs will cause lldpd to continually allocate memory and leak the old memory As an example, multiple instances of system name TLV will cause old values to be dropped by the decoding routine ...