First published: Fri Jul 09 2021(Updated: )
Multiple Out-of-Bound read vulnerability in SonicWall Switch when handling LLDP Protocol allows an attacker to cause a system instability or potentially read sensitive information from the memory locations.
Credit: PSIRT@sonicwall.com
Affected Software | Affected Version | How to fix |
---|---|---|
SonicWall Switch | <=1.0.0.5-16 | |
Sonicwall Sws12-10fpoe | ||
Sonicwall Sws12-8 | ||
Sonicwall Sws12-8poe | ||
Sonicwall Sws14-24 | ||
Sonicwall Sws14-24fpoe | ||
Sonicwall Sws14-48 | ||
Sonicwall Sws14-48fpoe |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-20024 is a vulnerability in SonicWall Switch that allows an attacker to cause system instability or potentially read sensitive information from memory locations.
CVE-2021-20024 has a severity rating of 8.1 (high).
SonicWall Switch versions up to and including 1.0.0.5-16 are affected by CVE-2021-20024.
CVE-2021-20024 can be exploited by sending malicious LLDP Protocol data to the SonicWall Switch.
There is no specific fix available for CVE-2021-20024 at the moment, but SonicWall recommends applying the latest firmware updates and following the recommended security best practices.