First published: Mon May 10 2021(Updated: )
Improper validation of the ChassisID TLV in userdisk/vport_lldpd in Moxa Camera VPort 06EC-2V Series, version 1.1, allows attackers to cause a denial of service due to a NULL pointer dereference via a crafted lldp packet.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Moxa VPort 06EC-2V26M | =1.1 | |
Moxa VPort 06EC-2V26M | ||
Moxa Vport 06ec-2v36m-t Firmware | =1.1 | |
Moxa Vport 06ec-2v36m-t Firmware | ||
Moxa Vport 06ec-2v36m-ct-t Firmware | =1.1 | |
Moxa Vport 06ec-2v36m-ct-t Firmware | ||
Moxa Vport 06ec-2v36m-ct-t Firmware | =1.1 | |
Moxa Vport 06ec-2v36m-ct-t Firmware | ||
Moxa Vport 06ec-2v42m Firmware | =1.1 | |
Moxa Vport 06ec-2v42m Firmware | ||
Moxa Vport 06ec-2v42m-t Firmware | =1.1 | |
Moxa Vport 06ec-2v42m-t Firmware | ||
Moxa Vport 06ec-2v42m-ct-t Firmware | =1.1 | |
Moxa VPort 06EC-2V42M-CT | ||
Moxa Vport 06ec-2v42m-t Firmware | =1.1 | |
Moxa Vport 06ec-2v42m-ct-t Firmware | ||
Moxa Vport 06ec-2v60m-t Firmware | =1.1 | |
Moxa Vport 06ec-2v60m-t Firmware | ||
Moxa Vport 06ec-2v60m-t Firmware | =1.1 | |
Moxa Vport 06ec-2v60m-t Firmware | ||
Moxa Vport 06ec-2v60m-ct-t | =1.1 | |
Moxa Vport 06ec-2v60m-ct-t | ||
Moxa Vport 06ec-2v60m-ct Firmware | =1.1 | |
Moxa VPort 06EC-2V60M-CT-T Firmware | ||
Moxa Vport 06ec-2v80m-t Firmware | =1.1 | |
Moxa Vport 06ec-2v80m-t Firmware | ||
Moxa Vport 06ec-2v80m-t Firmware | =1.1 | |
Moxa Vport 06ec-2v80m-t Firmware | ||
Moxa Vport 06ec-2v80m Firmware | =1.1 | |
Moxa Vport 06ec-2v80m Firmware | ||
Moxa Vport 06ec-2v80m-ct-t | =1.1 | |
Moxa Vport 06ec-2v80m-ct-t Firmware |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-25845 has been assigned a CVSS severity score of medium due to its potential to cause denial of service.
To mitigate CVE-2021-25845, update the firmware of affected Moxa VPort 06EC-2V Series devices to the latest version provided by Moxa.
CVE-2021-25845 specifically affects Moxa VPort 06EC-2V Series devices running firmware version 1.1.
CVE-2021-25845 can be exploited by sending crafted LLDP packets that cause a NULL pointer dereference.
Exploitation of CVE-2021-25845 can lead to a denial of service condition, impacting the availability of the device.