Cisco Optical Networking System and Transport Controller Multiple Vulnerabilities
BID:17384
Info
Cisco Optical Networking System and Transport Controller Multiple Vulnerabilities
| Bugtraq ID: | 17384 |
| Class: | Unknown |
| CVE: | |
| Remote: | Yes |
| Local: | Yes |
| Published: | Apr 05 2006 12:00AM |
| Updated: | Apr 06 2006 05:23PM |
| Credit: | These issues were disclosed by the vendor. |
| Vulnerable: |
Cisco Transport Controller 4.0.x Cisco ONS 15600 Series 0 Cisco ONS 15600 1.3 (0) Cisco ONS 15600 1.1 (1) Cisco ONS 15600 1.1 (0) Cisco ONS 15600 1.1 Cisco ONS 15600 1.0 Cisco ONS 15454 MSTP 0 Cisco ONS 15454 MSPP 0 Cisco ONS 15327 4.14 Cisco ONS 15327 4.6 (1) Cisco ONS 15327 4.6 (0) Cisco ONS 15327 4.1 (3) Cisco ONS 15327 4.1 (2) Cisco ONS 15327 4.1 (1) Cisco ONS 15327 4.1 (0) Cisco ONS 15327 4.0 (2) Cisco ONS 15327 4.0 (1) Cisco ONS 15327 4.0 Cisco ONS 15327 3.4 Cisco ONS 15327 3.3 Cisco ONS 15327 3.2 Cisco ONS 15327 3.1 Cisco ONS 15327 3.0 Cisco ONS 15310-CL Series 0 |
| Not Vulnerable: |
Cisco Transport Controller 4.1 Cisco ONS 15800 Series 0 Cisco ONS 15500 Series 0 Cisco ONS 15310-MA 0 Cisco ONS 15305 0 Cisco ONS 15302 Cisco ONS 15200 Series 0 Cisco ONS 15100 Series 0 |
Discussion
Cisco Optical Networking System and Transport Controller Multiple Vulnerabilities
Cisco Optical Networking System and Transport Controller are prone to multiple vulnerabilities.
Cisco Optical Networking System 15000 series are affected by multiple denial-of-service vulnerabilities.
Cisco Transport Controller is prone to an arbitrary code-execution vulnerability.
Cisco Optical Networking System and Transport Controller are prone to multiple vulnerabilities.
Cisco Optical Networking System 15000 series are affected by multiple denial-of-service vulnerabilities.
Cisco Transport Controller is prone to an arbitrary code-execution vulnerability.
Exploit / POC
Cisco Optical Networking System and Transport Controller Multiple Vulnerabilities
An attacker uses readily available network utilities to exploit the denial-of-service vulnerabilities. Exploit code is not required to trigger the remote code-execution vulnerability.
An attacker uses readily available network utilities to exploit the denial-of-service vulnerabilities. Exploit code is not required to trigger the remote code-execution vulnerability.
Solution / Fix
Cisco Optical Networking System and Transport Controller Multiple Vulnerabilities
Solution:
The vendor has released fixes to address these issues. Please see the referenced vendor advisory for further information.
Solution:
The vendor has released fixes to address these issues. Please see the referenced vendor advisory for further information.
References
Cisco Optical Networking System and Transport Controller Multiple Vulnerabilities
References:
References: