Memory leak in Cisco Video Surveillance 7000 Series IP Cameras - CVE-2021-1596

 

Memory leak in Cisco Video Surveillance 7000 Series IP Cameras - CVE-2021-1596

Published: July 8, 2021


Vulnerability identifier: #VU54613
CSH Severity: Low
CVSS v4: 7.1 [CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2021-1596
CWE-ID: CWE-401
Exploitation vector: Adjecent network
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform DoS attack on the target system.

The vulnerability exists due memory leak in the Link Layer Discovery Protocol (LLDP) implementation. A remote attacker on the local network can send specially crafted LLDP packets and perform denial of service attack.


Affected software

Cisco Video Surveillance 7000 Series IP Cameras

How to mitigate CVE-2021-1596

Install updates from vendor's website.

Cisco Video Surveillance 7000 Series IP Cameras - update to 2.12.4

External References

Related Security Bulletins