CVE-2014-8425: Infoleak
Published Nov 28, 2014
·Updated
The management portal in ARRIS VAP2500 before FW08.41 allows remote attackers to obtain credentials by reading the configuration files.
Affected Software
1 affected component
Arris Vap2500 Firmware<=08.41
Event History
Nov 28, 2014
CVE Published
via MITRE·03:00 PM
Data Sourced
via MITRE·03:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2014-8425?
CVE-2014-8425 has been classified as a medium severity vulnerability.
2
How do I fix CVE-2014-8425?
To fix CVE-2014-8425, upgrade the firmware of the ARRIS VAP2500 to version FW08.42 or later.
3
What type of attack does CVE-2014-8425 allow?
CVE-2014-8425 allows remote attackers to obtain sensitive configuration credentials.
4
Which devices are affected by CVE-2014-8425?
CVE-2014-8425 affects the ARRIS VAP2500 management portal prior to firmware version FW08.42.
5
Is CVE-2014-8425 a known vulnerability?
Yes, CVE-2014-8425 is a publicly disclosed vulnerability affecting certain firmware versions of the ARRIS VAP2500.