QID 730223
Date Published: 2021-10-07
QID 730223: Cisco Small Business 220 Series Smart Switches Link Layer Discovery Protocol Vulnerabilities (cisco-sa-sb220-lldp-multivuls-mVRUtQ8T)
Multiple vulnerabilities exist in the Link Layer Discovery Protocol (LLDP) implementation for Cisco Small Business 220 Series Smart Switches.
Affected Products
Cisco Small Business 220 Series Smart Switches if they are running a vulnerable firmware release and
have the LLDP feature enabled.
Note: LLDP is enabled by default on all LAN ports on Cisco Small Business 220 Series Smart Switches.
QID Detection Logic (UnAuthenticated):
The unauthenticated check tries to fetch the Cisco Smart Switch vulnerable version in response to GET request to an API,but not the model number.
On Successful exploitation, an unauthenticated, adjacent attacker could perform the following:
Execute code on the affected device or cause it to reload unexpectedly
Cause LLDP database corruption on the affected device
Customers are advised to refer to cisco-sa-sb220-lldp-multivuls-mVRUtQ8T for more information.
- cisco-sa-sb220-lldp-multivuls-mVRUtQ8T -
tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sb220-lldp-multivuls-mVRUtQ8T
CVEs related to QID 730223
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| cisco-sa-sb220-lldp-multivuls-mVRUtQ8T |
|