Vulnerability Description
The Arris Touchstone DG950A cable modem with software 7.10.131 has an SNMP community of public, which allows remote attackers to obtain sensitive password, key, and SSID information via an SNMP request.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Arris | Touchstone Dg950A Software | 7.10.131 |
| Arris | Touchstone Dg950A | - |
Related Weaknesses (CWE)
References
- http://www.kb.cert.org/vuls/id/855836US Government Resource
- https://community.rapid7.com/community/metasploit/blog/2014/08/21/more-snmp-infoExploit
- http://www.kb.cert.org/vuls/id/855836US Government Resource
- https://community.rapid7.com/community/metasploit/blog/2014/08/21/more-snmp-infoExploit
FAQ
What is CVE-2014-4863?
CVE-2014-4863 is a vulnerability with a CVSS score of 5.0 (MEDIUM). The Arris Touchstone DG950A cable modem with software 7.10.131 has an SNMP community of public, which allows remote attackers to obtain sensitive password, key, and SSID information via an SNMP reques...
How severe is CVE-2014-4863?
CVE-2014-4863 has been rated MEDIUM with a CVSS base score of 5.0/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2014-4863?
Check the references section above for vendor advisories and patch information. Affected products include: Arris Touchstone Dg950A Software, Arris Touchstone Dg950A.