8.3
CVSSv2

CVE-2021-1309

Published: 08/04/2021 Updated: 07/11/2023
CVSS v2 Base Score: 8.3 | Impact Score: 10 | Exploitability Score: 6.5
CVSS v3 Base Score: 8.8 | Impact Score: 5.9 | Exploitability Score: 2.8
VMScore: 739
Vector: AV:A/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Summary

Multiple vulnerabilities exist in the Link Layer Discovery Protocol (LLDP) implementation for Cisco Small Business RV Series Routers. An unauthenticated, adjacent attacker could execute arbitrary code or cause an affected router to leak system memory or reload. A memory leak or device reload would cause a denial of service (DoS) condition on an affected device. For more information about these vulnerabilities, see the Details section of this advisory. Note: LLDP is a Layer 2 protocol. To exploit these vulnerabilities, an attacker must be in the same broadcast domain as the affected device (Layer 2 adjacent).

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

cisco rv132w_firmware 1.0.0.14

cisco rv132w_firmware 1.0.1.14

cisco rv132w_firmware 1.0.1.20

cisco rv134w_firmware 1.0.0.14

cisco rv134w_firmware 1.0.1.14

cisco rv134w_firmware 1.0.1.20

cisco rv160_firmware 1.0.0.14

cisco rv160_firmware 1.0.1.14

cisco rv160_firmware 1.0.1.20

cisco rv160w_firmware 1.0.0.14

cisco rv160w_firmware 1.0.1.14

cisco rv160w_firmware 1.0.1.20

cisco rv260_firmware 1.0.0.14

cisco rv260_firmware 1.0.1.14

cisco rv260_firmware 1.0.1.20

cisco rv260p_firmware 1.0.0.14

cisco rv260p_firmware 1.0.1.14

cisco rv260p_firmware 1.0.1.20

cisco rv260w_firmware 1.0.0.14

cisco rv260w_firmware 1.0.1.14

cisco rv260w_firmware 1.0.1.20

cisco rv340_firmware 1.0.0.14

cisco rv340_firmware 1.0.1.14

cisco rv340_firmware 1.0.1.20

cisco rv340w_firmware 1.0.0.14

cisco rv340w_firmware 1.0.1.14

cisco rv340w_firmware 1.0.1.20

cisco rv345_firmware 1.0.0.14

cisco rv345_firmware 1.0.1.14

cisco rv345_firmware 1.0.1.20

cisco rv345p_firmware 1.0.0.14

cisco rv345p_firmware 1.0.1.14

cisco rv345p_firmware 1.0.1.20

Vendor Advisories

Multiple vulnerabilities exist in the Link Layer Discovery Protocol (LLDP) implementation for Cisco Small Business RV Series Routers An unauthenticated, adjacent attacker could execute arbitrary code or cause an affected router to leak system memory or reload A memory leak or device reload would cause a denial of service (DoS) condition on an aff ...