CVE-2004-0306
Summary
| CVE | CVE-2004-0306 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2004-11-23 05:00:00 UTC |
| Updated | 2025-04-03 01:03:51 UTC |
| Description | Cisco ONS 15327 before 4.1(3), ONS 15454 before 4.6(1), ONS 15454 SD before 4.1(3), and Cisco ONS 15600 before 1.3(0) enable TFTP service on UDP port 69 by default, which allows remote attackers to GET or PUT ONS system files on the current active TCC in the /flash0 or /flash1 directories. |
Risk And Classification
Primary CVSS: v2.0 5 from [email protected]
AV:N/AC:L/Au:N/C:N/I:P/A:N
Problem Types: NVD-CWE-Other | n/a
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
LowAuthentication
NoneConfidentiality
NoneIntegrity
PartialAvailability
NoneAV:N/AC:L/Au:N/C:N/I:P/A:N
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Cisco | Optical Networking Systems Software | 1.0 | All | All | All |
| Application | Cisco | Optical Networking Systems Software | 4.0.0 | All | All | All |
| Application | Cisco | Optical Networking Systems Software | 4.0\(1\) | All | All | All |
| Application | Cisco | Optical Networking Systems Software | 4.0\(2\) | All | All | All |
| Application | Cisco | Optical Networking Systems Software | 4.1.0 | All | All | All |
| Application | Cisco | Optical Networking Systems Software | 4.1\(0\) | All | All | All |
| Application | Cisco | Optical Networking Systems Software | 4.1\(1\) | All | All | All |
| Application | Cisco | Optical Networking Systems Software | 4.1\(2\) | All | All | All |
| Application | Cisco | Optical Networking Systems Software | 4.1\(3\) | All | All | All |
| Application | Cisco | Optical Networking Systems Software | 4.5 | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| IBM X-Force Exchange | af854a3a-2127-422b-91ae-364da2661108 | exchange.xforce.ibmcloud.com | |
| Cisco ONS Platform Vulnerabilities | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | Patch, Vendor Advisory |
| Cisco - Networking, Cloud, and Cybersecurity Solutions | af854a3a-2127-422b-91ae-364da2661108 | www.cisco.com | Patch, Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.