The TRENDnet TI-PG1284i switch(hw v2.0R) prior to version 2.0.2.S0 suffers from a null pointer dereference vulnerability. This vulnerability exists in its lldp related component. Due to fail to check if ChassisID TLV is contained in the packet, by sending a crafted lldp packet to the device, an attacker can crash the process due to null pointer dereference.
References
Link Resource
https://www.trendnet.com/support/view.asp?cat=4&id=81 Patch Vendor Advisory
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: mitre

Published: 2022-05-11T17:34:25

Updated: 2022-05-11T17:34:25

Reserved: 2021-05-20T00:00:00


Link: CVE-2021-33317

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2022-05-11T18:15:22.783

Modified: 2022-05-20T15:38:02.560


Link: CVE-2021-33317

JSON object: View

cve-icon Redhat Information

No data.

CWE