Integer Underflow in TRENDnet TI-PG1284i Switch
CVE-2021-33315
9.8CRITICAL
What is CVE-2021-33315?
The TRENDnet TI-PG1284i switch (hw v2.0R) is impacted by an integer underflow vulnerability within its LLDP component. This flaw arises from inadequate validation of the length field in the PortID TLV. An attacker can exploit this vulnerability by sending a specially crafted LLDP packet to the device. This leads to an integer underflow condition, allowing a negative value to be processed by the memcpy() function, which may lead to a buffer overflow or result in invalid memory access, potentially compromising the integrity and availability of the system.
References
CVSS V3.1
Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved