SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2014-2004

The PPP Access Concentrator (PPPAC) on SEIL SEIL/x86 routers 1.00 through 3.10, SEIL/X1 routers 1.00 through 4.50, SEIL/X2 routers 1.00 through 4.50, SEIL/B1 routers 1.00 through 4.50, SEIL/Turbo routers 1.80 through 2.17, and SEIL/neu 2FE Plus routers…

MEDIUM 5.0EPSS 2.14%

Does this matter?

Lower severity and a low EPSS score (2.14%). Track it; it rarely justifies an emergency change on its own.

Description

The PPP Access Concentrator (PPPAC) on SEIL SEIL/x86 routers 1.00 through 3.10, SEIL/X1 routers 1.00 through 4.50, SEIL/X2 routers 1.00 through 4.50, SEIL/B1 routers 1.00 through 4.50, SEIL/Turbo routers 1.80 through 2.17, and SEIL/neu 2FE Plus routers 1.80 through 2.17 allows remote attackers to cause a denial of service (session termination or concentrator outage) via a crafted TCP packet.

CVSS 2.0
5.0 MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
EPSS
2.14% probability · 81th percentile
CISA KEV
Not listed
Weakness
CWE-119
Affected
iij/seil\%2fturbo firmware · iij/seil\/turbo · iij/seil\%2fneu 2fe plus firmware · iij/seil\/neu 2fe plus · iij/seil\%2fx86 firmware · iij/seil\/x86 · iij/seil\%2fx2 firmware · iij/seil\/x2 · iij/seil\%2fx1 firmware · iij/seil\/x1 · iij/seil\%2fb1 firmware · iij/seil\/b1
Source
vultures@jpcert.or.jp

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.