CVE-2014-7997
The DHCP implementation in Cisco IOS on Aironet access points does not properly handle error conditions with short leases and unsuccessful lease-renewal attempts, which allows remote attackers to cause a denial of service (device restart) by triggering…
Does this matter?
Lower severity and a low EPSS score (0.69%). Track it; it rarely justifies an emergency change on its own.
Description
The DHCP implementation in Cisco IOS on Aironet access points does not properly handle error conditions with short leases and unsuccessful lease-renewal attempts, which allows remote attackers to cause a denial of service (device restart) by triggering a transition into a recovery state that was intended to involve a network-interface restart but actually involves a full device restart, aka Bug ID CSCtn16281.
- CVSS 2.0
- 6.1 MEDIUMAV:A/AC:L/Au:N/C:N/I:N/A:C
- EPSS
- 0.69% probability · 51th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-399
- Affected
- cisco/ios
- Source
- psirt@cisco.com
References
- http://tools.cisco.com/security/center/content/CiscoSecurityNotice/CVE-2014-7997Vendor Advisory
- http://www.securitytracker.com/id/1031218
- https://exchange.xforce.ibmcloud.com/vulnerabilities/98691
- http://tools.cisco.com/security/center/content/CiscoSecurityNotice/CVE-2014-7997Vendor Advisory
- http://www.securitytracker.com/id/1031218
- https://exchange.xforce.ibmcloud.com/vulnerabilities/98691
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.