Cyber Resilience

CVE-2021-33317

High

Published: 11 May 2022

Published
11 May 2022
Modified
21 November 2024
KEV Added
Patch
CVSS Score v3.1 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
EPSS Score 0.0046 64.4th percentile
Risk Priority 15 60% EPSS · 20% KEV · 20% CVSS

Summary

CVE-2021-33317 is a high-severity NULL Pointer Dereference (CWE-476) vulnerability in Trendnet Ti-Pg1284I Firmware. Its CVSS base score is 7.5 (High).

Operationally, ranked in the top 35.6% of CVEs by exploit likelihood; it is not currently listed in the CISA KEV catalog.

EU & UK References

Vulnerability details

The TRENDnet TI-PG1284i switch(hw v2.0R) prior to version 2.0.2.S0 suffers from a null pointer dereference vulnerability. This vulnerability exists in its lldp related component. Due to fail to check if ChassisID TLV is contained in the packet, by sending a…

more

crafted lldp packet to the device, an attacker can crash the process due to null pointer dereference.

CWE(s)

Related Threats

No named actor attribution yet. ATT&CK technique mapping in progress for this CVE.

Affected Assets

trendnet
ti-pg1284i firmware
≤ 2.0.2.s0
trendnet
ti-g102i firmware
all versions
trendnet
ti-g160i firmware
all versions
trendnet
ti-g642i firmware
all versions
trendnet
ti-pg102i firmware
all versions
trendnet
ti-pg541i firmware
all versions
trendnet
ti-rp262i firmware
all versions
trendnet
teg-30102ws firmware
all versions
trendnet
tpe-30102ws firmware
all versions

Mitigating Controls

No mitigating controls mapped yet. The per-CVE control annotator has not reached this CVE.

References