VulnerabilityModified
CVE-2014-7992
The DLSw implementation in Cisco IOS does not initialize packet buffers, which allows remote attackers to obtain sensitive credential information from process memory via a session on TCP port 2067, aka Bug ID CSCur14014.
MEDIUM 5.0EPSS 27.2%
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 27.2%, higher than 98% of all known CVEs. Patch or mitigate before the next change window.
Description
The DLSw implementation in Cisco IOS does not initialize packet buffers, which allows remote attackers to obtain sensitive credential information from process memory via a session on TCP port 2067, aka Bug ID CSCur14014.
- CVSS 2.0
- 5.0 MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
- EPSS
- 27.15% probability · 98th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-200
- Affected
- cisco/ios
- Source
- psirt@cisco.com
References
- http://tools.cisco.com/security/center/content/CiscoSecurityNotice/CVE-2014-7992Vendor Advisory
- http://tools.cisco.com/security/center/viewAlert.x?alertId=36453Vendor Advisory
- http://www.securityfocus.com/bid/71145
- http://www.securitytracker.com/id/1031220
- https://exchange.xforce.ibmcloud.com/vulnerabilities/98724
- http://tools.cisco.com/security/center/content/CiscoSecurityNotice/CVE-2014-7992Vendor Advisory
- http://tools.cisco.com/security/center/viewAlert.x?alertId=36453Vendor Advisory
- http://www.securityfocus.com/bid/71145
- http://www.securitytracker.com/id/1031220
- https://exchange.xforce.ibmcloud.com/vulnerabilities/98724
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.