CVE-2014-7992
Cisco DLSw Information Disclosure Scanner
Title source: metasploitDescription
The DLSw implementation in Cisco IOS does not initialize packet buffers, which allows remote attackers to obtain sensitive credential information from process memory via a session on TCP port 2067, aka Bug ID CSCur14014.
Exploits (1)
metasploit
SCANNER
by Tate Hansen, John McLeod, Kyle Rainey · rubypoc
https://github.com/rapid7/metasploit-framework/blob/master/modules/auxiliary/scanner/dlsw/dlsw_leak_capture.rb
References (5)
Scores
EPSS
0.6080
EPSS Percentile
98.3%
Details
CWE
CWE-200
Status
published
Products (1)
cisco/ios
Published
Nov 18, 2014
Tracked Since
Feb 18, 2026