CVE-2012-2514 describes a denial-of-service vulnerability in the DiagiEventSource function of disp+work.exe within the Dispatcher component of SAP NetWeaver 7.0 EHP1 and EHP2. An unauthenticated remote attacker can exploit this flaw by sending a specially crafted SAP Diag packet, leading to a daemon crash and service disruption. The vulnerability has a CVSS score of 5.0, indicating a medium severity with low attack complexity and no authentication required, resulting in a partial impact on availability. While not listed in KEV, exploit code is publicly available through ExploitDB, though there is no evidence of active exploitation, Metasploit modules, or significant community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
7.0CPE matchmatch criteria | cpe:2.3:a:sap:netweaver:7.0:ehp1:*:*:*:*:*:* | ||
7.0CPE matchmatch criteria | cpe:2.3:a:sap:netweaver:7.0:ehp2:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:N/C:N/I:N/A:P
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.