MEDIUM · 5.0

CVE-2014-7992

The DLSw implementation in Cisco IOS does not initialize packet buffers, which allows remote attackers to obtain sensitive credential information from process memory via a session on TCP port 2067, ak...

Vulnerability Description

The DLSw implementation in Cisco IOS does not initialize packet buffers, which allows remote attackers to obtain sensitive credential information from process memory via a session on TCP port 2067, aka Bug ID CSCur14014.

CVSS Score

5.0

MEDIUM

AV:N/AC:L/Au:N/C:P/I:N/A:N
Confidentiality
PARTIAL
Integrity
NONE
Availability
NONE

Affected Products

VendorProductVersions
CiscoIos-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2014-7992?

CVE-2014-7992 is a vulnerability with a CVSS score of 5.0 (MEDIUM). The DLSw implementation in Cisco IOS does not initialize packet buffers, which allows remote attackers to obtain sensitive credential information from process memory via a session on TCP port 2067, ak...

How severe is CVE-2014-7992?

CVE-2014-7992 has been rated MEDIUM with a CVSS base score of 5.0/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2014-7992?

Check the references section above for vendor advisories and patch information. Affected products include: Cisco Ios.