CVE-2021-34776
Multiple vulnerabilities exist in the Link Layer Discovery Protocol (LLDP) implementation for Cisco Small Business 220 Series Smart Switches. An unauthenticated, adjacent attacker could perform the following: Execute code on the affected device or cause it to reload unexpectedly Cause LLDP database corruption on the affected device For more information about these vulnerabilities, see the Details section of this advisory. Note: LLDP is a Layer 2 protocol. To exploit these vulnerabilities, an attacker must be in the same broadcast domain as the affected device (Layer 2 adjacent). Cisco has released firmware updates that address these vulnerabilities.
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
- Puntuación base: 4.3
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.41%
- Percentil entre todas las CVEs puntuadas: 33
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (16)
CWE
- CWE-120
- CWE-120
Referencias
JSON original (NVD)
Mostrar
{
"id": "CVE-2021-34776",
"cveTags": [],
"metrics": {
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2021-34776",
"role": "CISA Coordinator",
"options": [
{
"exploitation": "none"
},
{
"automatable": "no"
},
{
"technicalImpact": "partial"
}
],
"version": "2.0.3",
"timestamp": "2024-11-07T21:40:16.739201Z"
}
}
],
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 2.9,
"accessVector": "ADJACENT_NETWORK",
"vectorString": "AV:A/AC:M/Au:N/C:N/I:P/A:N",
"authentication": "NONE",
"integrityImpact": "PARTIAL",
"accessComplexity": "MEDIUM",
"availabilityImpact": "NONE",
"confidentialityImpact": "NONE"
},
"acInsufInfo": false,
"impactScore": 2.9,
"baseSeverity": "LOW",
"obtainAllPrivilege": false,
"exploitabilityScore": 5.5,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
],
"cvssMetricV31": [
{
"type": "Secondary",
"source": "psirt@cisco.com",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 4.3,
"attackVector": "ADJACENT_NETWORK",
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N",
"integrityImpact": "LOW",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "NONE",
"privilegesRequired": "NONE",
"confidentialityImpact": "NONE"
},
"impactScore": 1.4,
"exploitabilityScore": 2.8
},
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 4.3,
"attackVector": "ADJACENT_NETWORK",
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N",
"integrityImpact": "LOW",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "NONE",
"privilegesRequired": "NONE",
"confidentialityImpact": "NONE"
},
"impactScore": 1.4,
"exploitabilityScore": 2.8
}
]
},
"affected": [
{
"source": "psirt@cisco.com",
"affectedData": [
{
"vendor": "Cisco",
"product": "Cisco Small Business 200 Series Smart Switches",
"versions": [
{
"status": "affected",
"version": "n/a"
}
]
}
]
}
],
"published": "2021-10-06T20:15:14.733",
"references": [
{
"url": "https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sb220-lldp-multivuls-mVRUtQ8T",
"tags": [
"Vendor Advisory"
],
"source": "psirt@cisco.com"
},
{
"url": "https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sb220-lldp-multivuls-mVRUtQ8T",
"tags": [
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Secondary",
"source": "psirt@cisco.com",
"description": [
{
"lang": "en",
"value": "CWE-120"
}
]
},
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "CWE-120"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "Multiple vulnerabilities exist in the Link Layer Discovery Protocol (LLDP) implementation for Cisco Small Business 220 Series Smart Switches. An unauthenticated, adjacent attacker could perform the following: Execute code on the affected device or cause it to reload unexpectedly Cause LLDP database corruption on the affected device For more information about these vulnerabilities, see the Details section of this advisory. Note: LLDP is a Layer 2 protocol. To exploit these vulnerabilities, an attacker must be in the same broadcast domain as the affected device (Layer 2 adjacent). Cisco has released firmware updates that address these vulnerabilities."
},
{
"lang": "es",
"value": "Se presentan varias vulnerabilidades en la implementación del Protocolo de Detección de la Capa de Enlace (LLDP) para Cisco Small Business 220 Series Smart Switches. Un atacante adyacente no autenticado podría llevar a cabo lo siguiente: Ejecutar código en el dispositivo afectado o causar su recarga inesperada. Causar una corrupción de la base de datos LLDP en el dispositivo afectado. Para obtener más información sobre estas vulnerabilidades, consulte la sección Details de este aviso. Nota: LLDP es un protocolo de capa 2. Para explotar estas vulnerabilidades, un atacante debe estar en el mismo dominio de difusión que el dispositivo afectado (adyacente a la capa 2). Cisco ha publicado actualizaciones de firmware que abordan estas vulnerabilidades"
}
],
"lastModified": "2026-06-17T03:56:32.740",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:cisco:business_220-8t-e-2g_firmware:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "8F57E1F8-E627-4113-A443-A6DB80236233",
"versionEndIncluding": "1.2.0.6"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:cisco:business_220-8t-e-2g:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "864B54D4-1DAC-4805-AB0C-12B4AF3AA2A5"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:cisco:business_220-8p-e-2g_firmware:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "FC2C7129-CEA2-49D5-9967-DC5D2AAD65FE",
"versionEndIncluding": "1.2.0.6"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:cisco:business_220-8p-e-2g:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "1D6B0BB2-6CCF-4C28-A8A6-2D83F8BAD16D"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:cisco:business_220-8fp-e-2g_firmware:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "716EF897-3C9C-408A-92FC-AFDF3F436C1A",
"versionEndIncluding": "1.2.0.6"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:cisco:business_220-8fp-e-2g:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "A732D0F9-0C3A-41F1-9CD7-6839878F11E8"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:cisco:business_220-16t-2g_firmware:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "0D7CA726-6C49-40E3-BAF8-1C3906548EFD",
"versionEndIncluding": "1.2.0.6"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:cisco:business_220-16t-2g:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "A796A4C0-1EC3-4D5D-8992-7C9C9EB64B7D"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:cisco:business_220-16p-2g_firmware:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "16987EB7-0097-462F-9ED6-BD99328069EE",
"versionEndIncluding": "1.2.0.6"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:cisco:business_220-16p-2g:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "53F2ACD8-7EEA-4FF5-91B3-2499A67C2A6B"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:cisco:business_220-24t-4g_firmware:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "50706ED0-C8BD-4300-A139-E3CD06D0F889",
"versionEndIncluding": "1.2.0.6"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:cisco:business_220-24t-4g:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "694AD646-37B9-413B-98E8-0D7E3638CF7B"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:cisco:business_220-24p-4g_firmware:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "7F8CC1AB-91D0-4073-911E-E8561DE61ED4",
"versionEndIncluding": "1.2.0.6"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:cisco:business_220-24p-4g:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "912D0893-5C74-498C-91F2-3BDE746658FF"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:cisco:business_220-24fp-4g_firmware:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "609956AC-1496-49D5-B9F4-620AA9B08FDB",
"versionEndIncluding": "1.2.0.6"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:cisco:business_220-24fp-4g:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "A783C843-285B-4811-8A58-9CE40DC9A156"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:cisco:business_220-48t-4g_firmware:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "620B645E-EEF3-4001-B42C-F0F8A4C5FF7E",
"versionEndIncluding": "1.2.0.6"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:cisco:business_220-48t-4g:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "972E3541-9384-4A5B-9528-9CE264A89779"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:cisco:business_220-48p-4g_firmware:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "7337547E-A891-45DD-B4B7-126080520F19",
"versionEndIncluding": "1.2.0.6"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:cisco:business_220-48p-4g:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "39E46FA4-73AF-4C90-83E0-E6882ED9F0DA"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:cisco:business_220-24t-4x_firmware:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "763C387F-1656-4D4A-9245-38E50819AA70",
"versionEndIncluding": "1.2.0.6"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:cisco:business_220-24t-4x:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "6B16A54C-FE26-41E8-B9C8-D20C55F95B9F"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:cisco:business_220-24p-4x_firmware:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "C0B4D510-E63C-428D-BBFD-524ADC88FA2E",
"versionEndIncluding": "1.2.0.6"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:cisco:business_220-24p-4x:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "D5F675E8-69BA-4C5D-A638-15070E4C3A95"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:cisco:business_220-24fp-4x_firmware:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "FE82D534-9E35-4F71-8E93-1255FF492AF0",
"versionEndIncluding": "1.2.0.6"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:cisco:business_220-24fp-4x:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "8F9AD8EC-96C2-4431-96A9-E297DC302C29"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:cisco:business_220-48t-4x_firmware:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "43CD76F1-08CB-4E2B-8CAA-A3483D87772B",
"versionEndIncluding": "1.2.0.6"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:cisco:business_220-48t-4x:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "9C849A07-4AE9-4593-A2F6-17014F672DC8"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:cisco:business_220-48p-4x_firmware:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "35CAE9D5-701D-4936-865D-04F16E61CF7F",
"versionEndIncluding": "1.2.0.6"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:cisco:business_220-48p-4x:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "7125313E-2FDB-4AC8-A84C-AD1837856436"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:cisco:business_220-48fp-4x_firmware:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "46BA6DCB-B5A0-460E-9F41-7367F076EE0E",
"versionEndIncluding": "1.2.0.6"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:cisco:business_220-48fp-4x:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "A9630B5B-14CA-4779-9080-7B3FE6EE5CB8"
}
],
"operator": "OR"
}
],
"operator": "AND"
}
],
"sourceIdentifier": "psirt@cisco.com"
}