CVE-2014-7997: Medium severity cisco ios vulnerability
The DHCP implementation in Cisco IOS on Aironet access points does not properly handle error conditions with short leases and unsuccessful lease-renewal attempts, which allows remote attackers to cause a denial of service (device restart) by triggering a transition into a recovery state that was intended to involve a network-interface restart but actually involves a full device restart, aka Bug ID CSCtn16281.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2014-7997?
The severity of CVE-2014-7997 is classified as high due to its potential to cause denial of service by triggering device restarts.
How do I fix CVE-2014-7997?
To fix CVE-2014-7997, update the Cisco IOS to the latest version that addresses this vulnerability.
Which Cisco products are affected by CVE-2014-7997?
CVE-2014-7997 affects Cisco IOS running on various Aironet access points.
What type of attack does CVE-2014-7997 facilitate?
CVE-2014-7997 allows remote attackers to conduct a denial of service attack by exploiting DHCP lease handling.
Is CVE-2014-7997 remotely exploitable?
Yes, CVE-2014-7997 can be exploited remotely without authentication.