#VU57115 Out-of-bounds read in Cisco Small Business 220 Series Smart Switches - CVE-2021-34778
Published: October 7, 2021
Cisco Small Business 220 Series Smart Switches
Cisco Systems, Inc
Description
The vulnerability allows a remote attacker to compromise the target system.
The vulnerability exists due to missing length validation checks when processing LLDP messages in the Link Layer Discovery Protocol. A remote attacker on the local network can send a specially crafted LLDP packet, trigger out-of-bounds read error and cause corruption in the internal LLDP database of the affected device.