Network Management

NCM vulnerability scanning on Cisco devices

Some Cisco devices are showing a potential vulnerability. This particular vulnerability does not affect specific device types or models.

First published date

10/17/2018 3:03 PM

Last published date

7/6/2020 2:35 PM

Overview

Some Cisco devices show a potential vulnerability, but this vulnerability does not affect specific device types or models.

Product section

Network Configuration Manager

Resolution

Network Configuration Manager (NCM) searches vulnerabilities related to Cisco IOS and Cisco ASA. 
NCM is looking for:

cpe:/o:cisco:ios:
cpe:/a:cisco:adaptive_security_appliance:
cpe:/o:cisco:adaptive_security_appliance:
cpe:/h:cisco:adaptive_security_appliance:
cpe:/a:cisco:adaptive_security_appliance_software:
cpe:/o:cisco:adaptive_security_appliance_software:
cpe:/h:cisco:adaptive_security_appliance_software:

Only announcements with similar CPE patterns are taken into account.
CVE-2014-7998 announcement matches to common Cisco IOS cpe:/o:cisco:ios: pattern.

That is the reason you would get a "potential” vulnerability for Cisco 2960 switch. 
NCM reports these “potential” vulnerabilities, and then the user should review and ignore the ones which are not applicable for a particular device.