CVE-2014-3976: a10networks Advanced Core Operating System

Medium severity, CVSS 5.0. EPSS: 11.6% chance of exploitation in the next 30 days.

Buffer overflow in A10 Networks Advanced Core Operating System (ACOS) before 2.7.0-p6 and 2.7.1 before 2.7.1-P1_55 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long session id in the URI to sys_reboot.html. NOTE: some of these details are obtained from third party information.

Affected products

  • a10networks Advanced Core Operating System: version 2.7.0 only; version 2.7.1 only

Published 2014-06-05. Last modified 2026-06-17.