CVE-2014-4863
Summary
| CVE | CVE-2014-4863 |
|---|---|
| State | PUBLISHED |
| Assigner | certcc |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2014-09-05 17:55:06 UTC |
| Updated | 2026-05-06 22:30:45 UTC |
| Description | The Arris Touchstone DG950A cable modem with software 7.10.131 has an SNMP community of public, which allows remote attackers to obtain sensitive password, key, and SSID information via an SNMP request. |
Risk And Classification
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
LowAuthentication
NoneConfidentiality
PartialIntegrity
NoneAvailability
NoneAV:N/AC:L/Au:N/C:P/I:N/A:N
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Hardware | Arris | Touchstone Dg950a | - | All | All | All |
| Application | Arris | Touchstone Dg950a Software | 7.10.131 | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| More SNMP Information Leaks: CVE-2014-4862 and ... | Rapid7 Community | af854a3a-2127-422b-91ae-364da2661108 | community.rapid7.com | Exploit |
| Vulnerability Note VU#855836 - Arris Touchstone cable modem information leakage vulnerabiliity | af854a3a-2127-422b-91ae-364da2661108 | www.kb.cert.org | US Government Resource |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.