Memory leak in Cisco Video Surveillance 7000 Series IP Cameras - CVE-2021-1595
Published: July 8, 2021
Vulnerability identifier: #VU54614
CSH Severity: Low
CVSS v4: 7.1 [CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2021-1595
CWE-ID: CWE-401
Exploitation vector: Adjecent network
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to perform DoS attack on the target system.
The vulnerability exists due memory leak in the Link Layer Discovery Protocol (LLDP) implementation. A remote attacker on the local network can send specially crafted LLDP packets and perform denial of service attack.
Affected software
Cisco Video Surveillance 7000 Series IP Cameras
How to mitigate CVE-2021-1595
Install updates from vendor's website.
Cisco Video Surveillance 7000 Series IP Cameras - update to 2.12.4