CVE-2004-1433
published 2004-12-31CVE-2004-1433: Multiple versions of Cisco ONS 15327, ONS 15454, and ONS 15454 SDH, including 4.6(0) and 4.6(1), 4.5(x), 4.1(0) to 4.1(3), 4.0(0) to 4.0(2), and earlier…
PriorityP421medium5CVSS 2.0
AVNACLAuNCNINAP
EPSS
4.09%
89.5th percentile
Multiple versions of Cisco ONS 15327, ONS 15454, and ONS 15454 SDH, including 4.6(0) and 4.6(1), 4.5(x), 4.1(0) to 4.1(3), 4.0(0) to 4.0(2), and earlier versions, and ONS 15600 1.x(x), allows remote attackers to cause a denial of service (control card reset) via malformed (1) TCP and (2) UDP packets.
Affected
24 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | ons_15327_ons_15454_ons_15454_sdh_and_ons_15600_malformed_packet | — | — |
| cisco | optical_networking_systems_software | — | — |
| cisco | optical_networking_systems_software | — | — |
| cisco | optical_networking_systems_software | — | — |
| cisco | optical_networking_systems_software | — | — |
| cisco | optical_networking_systems_software | — | — |
| cisco | optical_networking_systems_software | — | — |
| cisco | optical_networking_systems_software | — | — |
| cisco | optical_networking_systems_software | — | — |
| cisco | optical_networking_systems_software | — | — |
| cisco | optical_networking_systems_software | — | — |
| cisco | optical_networking_systems_software | — | — |
| cisco | optical_networking_systems_software | — | — |
| cisco | optical_networking_systems_software | — | — |
| cisco | optical_networking_systems_software | — | — |
| cisco | optical_networking_systems_software | — | — |
| cisco | optical_networking_systems_software | — | — |
| cisco | optical_networking_systems_software | — | — |
| cisco | optical_networking_systems_software | — | — |
| cisco | optical_networking_systems_software | — | — |
| cisco | optical_networking_systems_software | — | — |
| cisco | optical_networking_systems_software | — | — |
| cisco | optical_networking_systems_software | — | — |
| cisco | optical_networking_systems_software | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Cisco
Cisco ONS 15327, ONS 15454, ONS 15454 SDH, and ONS 15600 Malformed Packet Vulnerabilities
vendor_cisco·2004-07-21
CVE-2004-1432 Cisco ONS 15327, ONS 15454, ONS 15454 SDH, and ONS 15600 Malformed Packet Vulnerabilities
Cisco ONS 15327, ONS 15454, ONS 15454 SDH, and ONS 15600 Malformed Packet Vulnerabilities
Cisco has fixed multiple malformed packet vulnerabilities in the TCP/IP
stacks of Cisco ONS 15327 Edge Optical Transport Platform, the Cisco ONS 15454
Optical Transport Platform, the Cisco ONS 15454 SDH Multiplexer Platform, and
the Cisco ONS 15600 Multiservice Switching Platform.
These vulnerabilities are documented as the following Cisco bug IDs
CSCed06531 (IP)
CSCed86946 (ICMP)
CSCec88426/CSCec88508/CSCed85088/CSCeb07263/CSCec21429
(TCP)
CSCec59739/CSCed02439/CSCed22547 (Last-ACK)
CSCec88402/CSCed31918/CSCed83309/CSCec85982/CSCec21435/CSCee03697
(UDP)
CSCea16455/CSCea37089/CSCea37185 (SNMP)
CSCee27329 (passwd)
There are workarounds available to mitigate the exposure to these
vuln
Cisco
Cisco ONS 15327, ONS 15454, ONS 15454 SDH, and ONS 15600 Malformed Packet Vulnerabilities
vendor_cisco
CVE-2004-1433 Cisco ONS 15327, ONS 15454, ONS 15454 SDH, and ONS 15600 Malformed Packet Vulnerabilities
CVE-2004-1433: Cisco ONS 15327, ONS 15454, ONS 15454 SDH, and ONS 15600 Malformed Packet Vulnerabilities
Cisco has fixed multiple malformed packet vulnerabilities in the TCP/IP stacks of Cisco ONS 15327 Edge Optical Transport Platform, the Cisco ONS 15454 Optical Transport Platform, the Cisco ONS 15454 SDH Multiplexer Platform, and the Cisco ONS 15600 Multiservice Switching Platform. These vulnerabilities are documented as the following Cisco bug IDs CSCed06531 (IP) CSCed86946 (ICMP) CSCec88426/CSCec88508/CSCed85088/CSCeb07263/CSCec21429 (TCP) CSCec59739/CSCed02439/CSCed22547 (Last-ACK) CSCec88402/CSCed31918/CSCed83309/CSCec85982/CSCec21435/CSCee03697 (UDP) CSCea16455/CSCea37089/CSCea37185 (SNMP) CSCee27329 (passwd) There are
Bug IDs: CSCed06531, CSCed86946, CSCec88426, CSCec88508, CSCed85
GHSA
GHSA-9v3j-jcw4-4p22: Multiple versions of Cisco ONS 15327, ONS 15454, and ONS 15454 SDH, including 4
ghsa_unreviewed·2022-04-29
CVE-2004-1433 [MEDIUM] GHSA-9v3j-jcw4-4p22: Multiple versions of Cisco ONS 15327, ONS 15454, and ONS 15454 SDH, including 4
Multiple versions of Cisco ONS 15327, ONS 15454, and ONS 15454 SDH, including 4.6(0) and 4.6(1), 4.5(x), 4.1(0) to 4.1(3), 4.0(0) to 4.0(2), and earlier versions, and ONS 15600 1.x(x), allows remote attackers to cause a denial of service (control card reset) via malformed (1) TCP and (2) UDP packets.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://secunia.com/advisories/12117http://www.cisco.com/warp/public/707/cisco-sa-20040721-ons.shtmlhttp://www.kb.cert.org/vuls/id/486224http://www.kb.cert.org/vuls/id/800384http://www.securityfocus.com/bid/10768https://exchange.xforce.ibmcloud.com/vulnerabilities/16762https://exchange.xforce.ibmcloud.com/vulnerabilities/16764http://secunia.com/advisories/12117http://www.cisco.com/warp/public/707/cisco-sa-20040721-ons.shtmlhttp://www.kb.cert.org/vuls/id/486224http://www.kb.cert.org/vuls/id/800384http://www.securityfocus.com/bid/10768https://exchange.xforce.ibmcloud.com/vulnerabilities/16762https://exchange.xforce.ibmcloud.com/vulnerabilities/16764
2004-12-31
Published