CVE-2020-27827

HIGH

Lldpd < 1.0.8 - Denial of Service

Title source: rule

Description

A flaw was found in multiple versions of OpenvSwitch. Specially crafted LLDP packets can cause memory to be lost when allocating data to handle specific optional TLVs, potentially causing a denial of service. The highest threat from this vulnerability is to system availability.

Scores

CVSS v3 7.5
EPSS 0.0042
EPSS Percentile 61.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Classification

CWE
CWE-400
Status published

Affected Products (19)

lldpd_project/lldpd < 1.0.8
openvswitch/openvswitch < 2.6.9
redhat/openshift_container_platform
redhat/openstack
redhat/openstack
redhat/virtualization
redhat/enterprise_linux
redhat/enterprise_linux
fedoraproject/fedora
siemens/simatic_hmi_unified_comfort_panels_firmware < 17
siemens/simatic_net_cp_1243-1_firmware
siemens/simatic_net_cp_1243-8_irc_firmware
siemens/simatic_net_cp_1542sp-1_firmware
siemens/simatic_net_cp_1542sp-1_irc_firmware
siemens/simatic_net_cp_1543-1_firmware
... and 4 more

Timeline

Published Mar 18, 2021
Tracked Since Feb 18, 2026