VYPR
Unrated severityNVD Advisory· Published Nov 15, 2014· Updated May 6, 2026

CVE-2014-7997

CVE-2014-7997

Description

The DHCP implementation in Cisco IOS on Aironet access points does not properly handle error conditions with short leases and unsuccessful lease-renewal attempts, which allows remote attackers to cause a denial of service (device restart) by triggering a transition into a recovery state that was intended to involve a network-interface restart but actually involves a full device restart, aka Bug ID CSCtn16281.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

A DHCP flaw in Cisco IOS on Aironet APs can cause a full device restart, leading to denial of service.

Vulnerability

The DHCP implementation in Cisco IOS on Aironet access points fails to properly handle error conditions when short leases are used and lease-renewal attempts are unsuccessful. This triggers a transition into a recovery state intended for network-interface restart but results in a full device restart. The vulnerability is identified by Bug ID CSCtn16281 and affects Cisco IOS on Aironet APs; specific versions are detailed in the Cisco advisory [1].

Exploitation

An attacker with network access can send DHCP messages that cause lease-renewal failures. No authentication is required. By repeatedly triggering this condition, the attacker can force the device into the faulty recovery state, leading to multiple restarts.

Impact

Successful exploitation causes the access point to perform a full restart, resulting in denial of service. The device becomes temporarily unavailable until the reboot completes, disrupting network connectivity for clients.

Mitigation

Cisco has published a security advisory [1] that includes information on fixed software releases. Users should upgrade to the appropriate version as indicated in the advisory. No workarounds are documented. If no fix is applied, devices remain vulnerable.

AI Insight generated on May 23, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

3

News mentions

0

No linked articles in our index yet.