Executive brief
Multiple buffer overflow vulnerabilities exist in the Link Layer Discovery Protocol (LLDP) subsystem of Cisco IOS, IOS XE, and IOS XR software. An unauthenticated, adjacent attacker could exploit these by sending crafted LLDP packets to cause a denial of service or execute arbitrary code with elevated privileges.
Affected products
- Cisco IOS up to (including) 15.6.3m1
- Cisco IOS XE up to (including) 15.6.3m1
- Cisco IOS XR 4.1 up to (excluding) 5.1.3
- Rockwell Automation Stratix 5400/5410/5700/5900/8000/8300
Timeline
- 2018-03-28: disclosed: Initial Cisco Security Advisory date
- 2022-03-03: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
- 2022-03-03: other: Published to NVD
- 2022-03-17: other: CISA KEV due date for remediation