CVE-2014-4863
medium · 5The Arris Touchstone DG950A cable modem with software 7.10.131 has an SNMP community of public, which allows remote attackers to obtain sensitive password, key, and SSID information via an SNMP request.
5
CVSS
15.7%
EPSS (exploit prob.)
97th
EPSS percentile
2014-09-05
Published
AV:N/AC:L/Au:N/C:P/I:N/A:N
Weaknesses
CWE-200
Affected products
| Vendor | Product | Affected versions |
|---|---|---|
| arris | touchstone_dg950a_software | 7.10.131 |
| arris | touchstone_dg950a | all versions |
Check a specific version with /api/v1/cve/match.
References
- http://www.kb.cert.org/vuls/id/855836
- https://community.rapid7.com/community/metasploit/blog/2014/08/21/more-snmp-information-leaks-cve-2014-4862-and-cve-2014-4863
- http://www.kb.cert.org/vuls/id/855836
- https://community.rapid7.com/community/metasploit/blog/2014/08/21/more-snmp-information-leaks-cve-2014-4862-and-cve-2014-4863
Query this programmatically:
curl https://evil-db.io/api/v1/cve/CVE-2014-4863