First published: Mon May 10 2021(Updated: )
Improper validation of the length field of LLDP-MED TLV in userdisk/vport_lldpd in Moxa Camera VPort 06EC-2V Series, version 1.1, allows information disclosure to attackers due to using fixed loop counter variable without checking the actual available length via a crafted lldp packet.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Moxa VPort 06EC-2V26M | <=1.1 | |
Moxa VPort 06EC-2V26M | ||
Moxa Vport 06ec-2v36m-t Firmware | <=1.1 | |
Moxa Vport 06ec-2v36m-t Firmware | ||
Moxa Vport 06ec-2v36m-ct-t Firmware | <=1.1 | |
Moxa Vport 06ec-2v36m-ct-t Firmware | ||
Moxa Vport 06ec-2v36m-ct-t Firmware | <=1.1 | |
Moxa Vport 06ec-2v36m-ct-t Firmware | ||
Moxa Vport 06ec-2v42m Firmware | <=1.1 | |
Moxa Vport 06ec-2v42m Firmware | ||
Moxa Vport 06ec-2v42m-t Firmware | <=1.1 | |
Moxa Vport 06ec-2v42m-t Firmware | ||
Moxa Vport 06ec-2v42m-ct-t Firmware | <=1.1 | |
Moxa VPort 06EC-2V42M-CT | ||
Moxa Vport 06ec-2v42m-t Firmware | <=1.1 | |
Moxa Vport 06ec-2v42m-ct-t Firmware | ||
Moxa Vport 06ec-2v60m-t Firmware | <=1.1 | |
Moxa Vport 06ec-2v60m-t Firmware | ||
Moxa Vport 06ec-2v60m-t Firmware | <=1.1 | |
Moxa Vport 06ec-2v60m-t Firmware | ||
Moxa Vport 06ec-2v60m-ct-t | <=1.1 | |
Moxa Vport 06ec-2v60m-ct-t | ||
Moxa Vport 06ec-2v60m-ct Firmware | <=1.1 | |
Moxa VPort 06EC-2V60M-CT-T Firmware | ||
Moxa Vport 06ec-2v80m-t Firmware | <=1.1 | |
Moxa Vport 06ec-2v80m-t Firmware | ||
Moxa Vport 06ec-2v80m-t Firmware | <=1.1 | |
Moxa Vport 06ec-2v80m-t Firmware | ||
Moxa Vport 06ec-2v80m Firmware | <=1.1 | |
Moxa Vport 06ec-2v80m Firmware | ||
Moxa Vport 06ec-2v80m-ct-t | <=1.1 | |
Moxa Vport 06ec-2v80m-ct-t Firmware |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-25848 is classified as a medium severity vulnerability.
To address CVE-2021-25848, update the firmware of the Moxa VPort 06EC-2V Series cameras to a version higher than 1.1.
CVE-2021-25848 is an information disclosure vulnerability due to improper validation of length in LLDP-MED TLV.
CVE-2021-25848 affects the Moxa VPort 06EC-2V Series cameras running firmware version 1.1.
An attacker exploiting CVE-2021-25848 could gain unauthorized access to sensitive information through crafted LLDP packets.