CVE-2014-7992

Cisco DLSw Information Disclosure Scanner

Title source: metasploit

Description

The DLSw implementation in Cisco IOS does not initialize packet buffers, which allows remote attackers to obtain sensitive credential information from process memory via a session on TCP port 2067, aka Bug ID CSCur14014.

Exploits (1)

metasploit SCANNER
by Tate Hansen, John McLeod, Kyle Rainey · rubypoc
https://github.com/rapid7/metasploit-framework/blob/master/modules/auxiliary/scanner/dlsw/dlsw_leak_capture.rb

Scores

EPSS 0.6080
EPSS Percentile 98.3%

Details

CWE
CWE-200
Status published
Products (1)
cisco/ios
Published Nov 18, 2014
Tracked Since Feb 18, 2026