CVE-2014-7992: Cisco IOS

Medium severity, CVSS 5.0. EPSS: 27.2% chance of exploitation in the next 30 days.

The DLSw implementation in Cisco IOS does not initialize packet buffers, which allows remote attackers to obtain sensitive credential information from process memory via a session on TCP port 2067, aka Bug ID CSCur14014.

Affected products

  • Cisco IOS: affected versions not specified

Published 2014-11-18. Last modified 2026-06-17.