CVE-2021-25848
Improper validation of the length field of LLDP-MED TLV in userdisk/vport_lldpd in Moxa Camera VPort 06EC-2V Series, version 1.1, allows information disclosure to attackers due to using fixed loop counter variable without checking the actual available…
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (1.21%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Improper validation of the length field of LLDP-MED TLV in userdisk/vport_lldpd in Moxa Camera VPort 06EC-2V Series, version 1.1, allows information disclosure to attackers due to using fixed loop counter variable without checking the actual available length via a crafted lldp packet.
- CVSS 3.1
- 9.1 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H
- EPSS
- 1.21% probability · 67th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-125
- Affected
- moxa/vport 06ec-2v26m firmware · moxa/vport 06ec-2v36m-t firmware · moxa/vport 06ec-2v36m-ct firmware · moxa/vport 06ec-2v36m-ct-t firmware · moxa/vport 06ec-2v42m firmware · moxa/vport 06ec-2v42m-t firmware · moxa/vport 06ec-2v42m-ct firmware · moxa/vport 06ec-2v42m-ct-t firmware · moxa/vport 06ec-2v60m firmware · moxa/vport 06ec-2v60m-t firmware · moxa/vport 06ec-2v60m-ct firmware · moxa/vport 06ec-2v60m-ct-t firmware · moxa/vport 06ec-2v80m firmware · moxa/vport 06ec-2v80m-t firmware · moxa/vport 06ec-2v80m-ct firmware · moxa/vport 06ec-2v80m-ct-t firmware
- Source
- cve@mitre.org
References
- https://www.moxa.com/en/Vendor Advisory
- https://www.moxa.com/en/support/product-support/security-advisory/vport-06ec-2v-series-ip-cameras-vulnerabilitiesVendor Advisory
- https://www.moxa.com/en/Vendor Advisory
- https://www.moxa.com/en/support/product-support/security-advisory/vport-06ec-2v-series-ip-cameras-vulnerabilitiesVendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.