CVE-2021-33317: Null Pointer Dereference
The TRENDnet TI-PG1284i switch(hw v2.0R) prior to version 2.0.2.S0 suffers from a null pointer dereference vulnerability. This vulnerability exists in its lldp related component. Due to fail to check if ChassisID TLV is contained in the packet, by sending a crafted lldp packet to the device, an attacker can crash the process due to null pointer dereference.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is CVE-2021-33317?
CVE-2021-33317 is a null pointer dereference vulnerability in the TRENDnet TI-PG1284i switch prior to version 2.0.2.S0.
What is the severity of CVE-2021-33317?
The severity of CVE-2021-33317 is high, with a CVSS score of 7.5.
How does CVE-2021-33317 affect TRENDnet TI-PG1284i switch?
CVE-2021-33317 allows an attacker to cause a null pointer dereference in the lldp component of the TRENDnet TI-PG1284i switch.
Is TRENDnet TI-PG1284i switch version 2.0R affected by CVE-2021-33317?
No, TRENDnet TI-PG1284i switch version 2.0R is not affected by CVE-2021-33317.
How can I fix CVE-2021-33317?
Update your TRENDnet TI-PG1284i switch firmware to version 2.0.2.S0 or later to fix CVE-2021-33317.