CVE-2014-2537

high
Published 2014-03-18 · Modified 2026-05-06
CVSS v3
CVSS v2
7.8
VIR risk
7.8

Description

Memory leak in the TCP stack in the kernel in Sophos UTM before 9.109 allows remote attackers to cause a denial of service (memory consumption) via unspecified vectors.

Predictions

Exploit likelihood
20%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

vendor Authored 2026-05-27

Vendor advisory: cve@mitre.org — http://secunia.com/advisories/57344

vendor Authored 2026-05-27

Vendor advisory: cve@mitre.org — http://blogs.sophos.com/2014/02/20/utm-up2date-9-109/

Application impact

VendorProductVersionsFixed
sophosunified_threat_management_software{"endIncluding":"9.108"}
sophosunified_threat_management_software8.3
sophosunified_threat_management_software9.007
sophosunified_threat_management_software9.107

References

CWEs

CWE-399

Verify integrity in audit chain (admin only). AS-IS.