CVE-2014-7997: Cisco IOS

Medium severity, CVSS 6.1. EPSS: 0.7% chance of exploitation in the next 30 days.

The DHCP implementation in Cisco IOS on Aironet access points does not properly handle error conditions with short leases and unsuccessful lease-renewal attempts, which allows remote attackers to cause a denial of service (device restart) by triggering a transition into a recovery state that was intended to involve a network-interface restart but actually involves a full device restart, aka Bug ID CSCtn16281.

Affected products

  • Cisco IOS: affected versions not specified

Published 2014-11-15. Last modified 2026-06-17.