Hello,
Our Cisco Switch IOS is ALREADY updated to one of the unaffected IOS versions. A vulnerability scan was run and determined this IOS version is NOW vulnerable. How do we fix this issue if the fixed IOS version is already installed??
Vuln Scan Plugin ID: 108880 - Cisco IOS Software Link Layer Discovery Protocol Buffer Overflow Vulnerabilities (cisco-sa-20180328-lldp)
Synopsis:The remote device is missing a vendor-supplied security patch.
Description:According to its self-reported version, the IOS is affected by one or more vulnerabilities. Please see the included Cisco BIDs and the Cisco Security Advisory for more information.
Solution:Upgrade to the relevant fixed version referenced in Cisco bug ID(s) CSCvd73487 and CSCvd73664.
Plugin Output: Cisco bug ID : CSCvd73487/CSCvd73664
Installed release : 15.2(7)E A vulnerable configuration was discovered by using the following command(s): - show lldp
Cisco IOS, IOS XE, and IOS XR Software Link Layer Discovery Protocol Buffer Overflow Vulnerabilities:https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20180328-lldp#details
Thank you for your assistance.