VU#855836Third-party advisory
http://www.kb.cert.org/vuls/id/855836 CVE-2014-4863
Arris DG950A Cable Modem Wifi Enumeration
Record summary
CVE-2014-4863 has a selected CVSS score of 5.0; EIP currently links 1 catalogued exploit.
Description
The Arris Touchstone DG950A cable modem with software 7.10.131 has an SNMP community of public, which allows remote attackers to obtain sensitive password, key, and SSID information via an SNMP request.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
MetasploitArris DG950A Cable Modem Wifi EnumerationMetasploit auxiliary PoCby Deral "Percent_X" HeilandNot analyzed1 file
References
3community.rapid7.com
https://community.rapid7.com/community/metasploit/blog/2014/08/21/more-snmp-information-leaks-cve-2014-4862-and-cve-2014-4863 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2014-4863