CVE-2021-43612 describes an out-of-bounds heap read vulnerability in lldpd versions prior to 1.0.13, specifically within the sonmp_decode function when processing short SONMP packets. This flaw, affecting products like Fedora and lldpd, carries a high CVSS score of 7.5, indicating a network-based attack with low complexity that can lead to high availability impact. While no active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion has been observed, the vulnerability remains a concern for unpatched systems.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1.0.13CPE matchmatch criteria | cpe:2.3:a:lldpd_project:lldpd:*:*:*:*:*:*:*:* | ||
36CPE matchmatch criteria | cpe:2.3:o:fedoraproject:fedora:36:*:*:*:*:*:*:* | ||
37CPE matchmatch criteria | cpe:2.3:o:fedoraproject:fedora:37:*:*:*:*:*:*:* | ||
38CPE matchmatch criteria | cpe:2.3:o:fedoraproject:fedora:38:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.