Impact
The vulnerability is a classic buffer overflow in the LLDP daemon of NVIDIA Cumulus Linux. An unauthenticated attacker on an adjacent network can send specially crafted LLDP frames to overflow a buffer and potentially execute arbitrary code. The functional impact is that code may run with the privileges of the LLDP service, allowing the attacker to take control of the affected device. This weakness is categorized as CWE-120.
Affected Systems
NVIDIA Cumulus Linux, including the GA and LTS releases. No specific version range is listed in the advisory, so all installations of these releases are potentially affected.
Risk and Exploitability
The CVSS score of 7.5 grades the vulnerability as high severity, indicating substantial risk if exploited. The EPSS score is not available, and the vulnerability is not in the CISA KEV catalog, meaning there is no publicly known exploit at the time of writing. The attack vector is inferred to be local, requiring proximity to the same network segment to deliver malicious LLDP frames, but once the packets are received the exploitation does not need additional credentials.
OpenCVE Enrichment