The TRENDnet TI-PG1284i switch(hw v2.0R) prior to version 2.0.2.S0 suffers from a null pointer dereference vulnerability. This vulnerability exists in its lldp related component. Due to fail to check if ChassisID TLV is contained in the packet, by sending a crafted lldp packet to the device, an attacker can crash the process due to null pointer dereference.
Advisories
Source ID Title
EUVD EUVD EUVD-2021-20027 The TRENDnet TI-PG1284i switch(hw v2.0R) prior to version 2.0.2.S0 suffers from a null pointer dereference vulnerability. This vulnerability exists in its lldp related component. Due to fail to check if ChassisID TLV is contained in the packet, by sending a crafted lldp packet to the device, an attacker can crash the process due to null pointer dereference.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2024-08-03T23:50:41.433Z

Reserved: 2021-05-20T00:00:00

Link: CVE-2021-33317

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2022-05-11T18:15:22.783

Modified: 2024-11-21T06:08:40.580

Link: CVE-2021-33317

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.