Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2021-33315


The TRENDnet TI-PG1284i switch(hw v2.0R) prior to version 2.0.2.S0 suffers from an integer underflow vulnerability. This vulnerability exists in its lldp related component. Due to lack of proper validation on length field of PortID TLV, by sending a crafted lldp packet to the device, integer underflow would occur and the negative number will be passed to memcpy() later, which may cause buffer overflow or invalid memory access.


Published

2022-05-11T18:15:22.580

Last Modified

2024-11-21T06:08:40.260

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 9.8 (CRITICAL)

CVSSv2 Vector

AV:N/AC:L/Au:N/C:P/I:P/A:P

  • Access Vector: NETWORK
  • Access Complexity: LOW
  • Authentication: NONE
  • Confidentiality Impact: PARTIAL
  • Integrity Impact: PARTIAL
  • Availability Impact: PARTIAL
Exploitability Score

10.0

Impact Score

6.4

Weaknesses
  • Type: Primary
    CWE-20

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Operating System trendnet ti-pg1284i_firmware < 2.0.2.s0 Yes
Hardware trendnet ti-pg1284i 2.0r No
Operating System trendnet ti-g102i_firmware - Yes
Hardware trendnet ti-g102i - No
Operating System trendnet ti-g160i_firmware - Yes
Hardware trendnet ti-g160i - No
Operating System trendnet ti-g642i_firmware - Yes
Hardware trendnet ti-g642i - No
Operating System trendnet ti-pg102i_firmware - Yes
Hardware trendnet ti-pg102i - No
Operating System trendnet ti-pg541i_firmware - Yes
Hardware trendnet ti-pg541i - No
Operating System trendnet ti-rp262i_firmware - Yes
Hardware trendnet ti-rp262i - No
Operating System trendnet teg-30102ws_firmware - Yes
Hardware trendnet teg-30102ws - No
Operating System trendnet tpe-30102ws_firmware - Yes
Hardware trendnet tpe-30102ws - No

References