Executive brief
A format string vulnerability in the Link Layer Discovery Protocol (LLDP) subsystem of Cisco IOS, IOS XE, and IOS XR Software allows an unauthenticated, adjacent attacker to cause a denial of service or execute arbitrary code with elevated privileges. The vulnerability is triggered by processing malicious LLDP packets.
Affected products
- Cisco IOS up to (including) 15.6.3m1
- Cisco IOS XE up to (including) 15.6.3m1
- Cisco IOS XR 15.4(3)m4.1
- Rockwell Automation Stratix 5400/5410/5700/5900/8000/8300
Timeline
- 2018-03-28: disclosed: Initial Cisco advisory publication
- 2022-03-03: kev added: Added to CISA Known Exploited Vulnerabilities Catalog