CVE-2014-4863: Infoleak
Published Sep 5, 2014
·Updated
The Arris Touchstone DG950A cable modem with software 7.10.131 has an SNMP community of public, which allows remote attackers to obtain sensitive password, key, and SSID information via an SNMP request.
Affected Software
2 affected components
Arris Touchstone Dg950a Software=7.10.131
Arris Touchstone DG950A
Event History
Sep 5, 2014
CVE Published
via MITRE·05:00 PM
Data Sourced
via MITRE·05:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2014-4863?
CVE-2014-4863 is considered a medium severity vulnerability because it exposes sensitive information via SNMP.
2
How do I fix CVE-2014-4863?
To fix CVE-2014-4863, change the SNMP community string from 'public' to a more secure value.
3
Who is affected by CVE-2014-4863?
CVE-2014-4863 affects users of the Arris Touchstone DG950A cable modem running software version 7.10.131.
4
What type of attack does CVE-2014-4863 enable?
CVE-2014-4863 enables remote attackers to retrieve sensitive data like passwords and SSIDs through SNMP requests.
5
Is CVE-2014-4863 actively exploited?
There have been reports of active exploitation attempts against devices vulnerable to CVE-2014-4863.