First published: Wed Apr 07 2021(Updated: )
Multiple vulnerabilities exist in the Link Layer Discovery Protocol (LLDP) implementation for Cisco Small Business RV Series Routers. An unauthenticated, adjacent attacker could execute arbitrary code or cause an affected router to leak system memory or reload. A memory leak or device reload would cause a denial of service (DoS) condition on an affected device. For more information about these vulnerabilities, see the Details section of this advisory. Note: LLDP is a Layer 2 protocol. To exploit these vulnerabilities, an attacker must be in the same broadcast domain as the affected device (Layer 2 adjacent). Cisco has released software updates that address these vulnerabilities. There are no workarounds that address these vulnerabilities. This advisory is available at the following link: https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-rv-multi-lldp-u7e4chCe
Credit: Qian Chen Qihoo 360 Nirvan Team for reporting these vulnerabilities
Affected Software | Affected Version | How to fix |
---|---|---|
Cisco Small Business RV Series Router Firmware | =RV340, RV340W, RV345, and RV345P<1.0.03.22 and later1=RV320 and RV325<Refer to End-of-Sale and End-of-Life Announcement for the Cisco RV320 and RV325 Dual Gigabit WAN VPN Router.=RV160, RV160W, RV260, RV260P, and RV260W<1.0.01.03 and later=RV134W<1.0.1.21 and later=RV132W<1.0.1.15 and later | 1.0.03.22 and later1 Refer to End-of-Sale and End-of-Life Announcement for the Cisco RV320 and RV325 Dual Gigabit WAN VPN Router. 1.0.01.03 and later 1.0.1.21 and later 1.0.1.15 and later |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Contains the following vulnerabilities)
The severity of cisco-sa-rv-multi-lldp-u7e4chCe is high due to potential arbitrary code execution and system memory leaks.
To fix cisco-sa-rv-multi-lldp-u7e4chCe, update affected Cisco Small Business RV Series Routers to the latest recommended firmware version.
The affected products in cisco-sa-rv-multi-lldp-u7e4chCe include RV340, RV340W, RV345, RV345P, RV320, RV325, RV160, RV160W, RV260, RV260P, RV260W, RV134W, and RV132W.
No, cisco-sa-rv-multi-lldp-u7e4chCe requires an unauthenticated, adjacent attacker to exploit the vulnerabilities.
cisco-sa-rv-multi-lldp-u7e4chCe includes vulnerabilities related to arbitrary code execution, memory leaks, and device reloads.