QID 317074

Date Published: 2021-10-21

QID 317074: Cisco Internetwork Operating System (IOS) and IOS XE Software Link Layer Discovery Protocol Denial of Service (DoS) Vulnerability (cisco-sa-lldp-dos-sBnuHSjT)

A vulnerability in the Link Layer Discovery Protocol (LLDP) message parser of Cisco IOS Software and
Cisco IOS XE Software could allow an attacker to trigger a reload of an affected device,
resulting in a denial of service (DoS) condition.

Affected Products
Cisco devices if they were running a vulnerable release of Cisco IOS or IOS XE Software and had the LLDP feature enabled.
Note: The LLDP feature is disabled in Cisco IOS and IOS XE Software by default.

QID Detection Logic (Authenticated):
The check matches Cisco IOS XE version retrieved via Unix Auth using "show version" command.
QID Detection Logic (Unauthenticated):
The check matches Cisco IOS XE version retrieved via SNMP or TCP/IP Fingerprint or NTP or Telnet.

A successful exploit could allow the attacker to cause the affected device to crash, resulting in a reload of the device.

  • CVSS V3 rated as High - 6.5 severity.
  • CVSS V2 rated as High - 6.8 severity.
  • Solution

    Customers are advised to refer to cisco-sa-lldp-dos-sBnuHSjT for more information.

    CVEs related to QID 317074

    Software Advisories
    Advisory ID Software Component Link
    cisco-sa-lldp-dos-sBnuHSjT URL Logo tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-lldp-dos-sBnuHSjT