CVE-2006-1671
published 2006-04-07CVE-2006-1671: Control cards for Cisco Optical Networking System (ONS) 15000 series nodes before 20060405 allow remote attackers to cause a denial of service (card reset) via…
PriorityP425medium5CVSS 2.0
AVNACLAuNCNINAP
EPSS
2.38%
82.0th percentile
Control cards for Cisco Optical Networking System (ONS) 15000 series nodes before 20060405 allow remote attackers to cause a denial of service (card reset) via (1) a "crafted" IP packet to a device with secure mode EMS-to-network-element access, aka bug ID CSCsc51390; (2) a "crafted" IP packet to a device with IP on the LAN interface, aka bug ID CSCsd04168; and (3) a "malformed" OSPF packet, aka bug ID CSCsc54558.
Affected
24 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | ons_15310-cl_series | — | — |
| cisco | ons_15600 | — | — |
| cisco | optical_networking_system_15000_series_and_cisco_transport_controller | — | — |
| cisco | optical_networking_systems_software | — | — |
| cisco | optical_networking_systems_software | — | — |
| cisco | optical_networking_systems_software | — | — |
| cisco | optical_networking_systems_software | — | — |
| cisco | optical_networking_systems_software | — | — |
| cisco | optical_networking_systems_software | — | — |
| cisco | optical_networking_systems_software | — | — |
| cisco | optical_networking_systems_software | — | — |
| cisco | optical_networking_systems_software | — | — |
| cisco | optical_networking_systems_software | — | — |
| cisco | optical_networking_systems_software | — | — |
| cisco | optical_networking_systems_software | — | — |
| cisco | optical_networking_systems_software | — | — |
| cisco | optical_networking_systems_software | — | — |
| cisco | optical_networking_systems_software | — | — |
| cisco | optical_networking_systems_software | — | — |
| cisco | optical_networking_systems_software | — | — |
| cisco | optical_networking_systems_software | — | — |
| cisco | optical_networking_systems_software | — | — |
| cisco | optical_networking_systems_software | — | — |
| cisco | transport_controller | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Cisco
Cisco Optical Networking System 15000 Series and Cisco Transport Controller Vulnerabilities
vendor_cisco·2006-04-05
CVE-2006-1670 CWE-399 Cisco Optical Networking System 15000 Series and Cisco Transport Controller Vulnerabilities
Cisco Optical Networking System 15000 Series and Cisco Transport Controller Vulnerabilities
Multiple vulnerabilities exist in the Cisco Optical Networking System
(ONS) 15310 Multi-service Provisioning Platforms (MSPP), ONS 15327 MSPP, ONS
15454 MSPP, ONS 15454 Multi-service Transport Platform (MSTP) and the ONS 15600
MSPP. These vulnerabilities will affect Optical nodes that have the Common
Control Cards connected to a Data Communications Network (DCN) and are enabled
for Internet Protocol Version 4 (IP). Successful exploitation of these
vulnerabilities will result in a denial of service (DoS) of the Common Control
Cards.
A separate vulnerability exists within the Cisco Transport Controller
(CTC) applet launcher which may allow execution of arbitrary code on the CTC
workstation. This so
Cisco
Cisco Optical Networking System 15000 Series and Cisco Transport Controller Vulnerabilities
vendor_cisco
CVE-2006-1671 Cisco Optical Networking System 15000 Series and Cisco Transport Controller Vulnerabilities
CVE-2006-1671: Cisco Optical Networking System 15000 Series and Cisco Transport Controller Vulnerabilities
Multiple vulnerabilities exist in the Cisco Optical Networking System (ONS) 15310 Multi-service Provisioning Platforms (MSPP), ONS 15327 MSPP, ONS 15454 MSPP, ONS 15454 Multi-service Transport Platform (MSTP) and the ONS 15600 MSPP. These vulnerabilities will affect Optical nodes that have the Common Control Cards connected to a Data Communications Network (DCN) and are enabled for Internet Protocol Version 4 (IP). Successful exploitation of these vulnerabilities will result in a denial of service (DoS) of the Common Control Cards. A separate vulnerability exists within the Cisco Transport Controller (CTC) applet launcher which may allow execution of arbitrary code on the CTC workstat
GHSA
GHSA-58gc-2cp7-m5wg: Control cards for Cisco Optical Networking System (ONS) 15000 series nodes before 20060405 allow remote attackers to cause a denial of service (card r
ghsa_unreviewed·2022-05-01
CVE-2006-1671 [MEDIUM] GHSA-58gc-2cp7-m5wg: Control cards for Cisco Optical Networking System (ONS) 15000 series nodes before 20060405 allow remote attackers to cause a denial of service (card r
Control cards for Cisco Optical Networking System (ONS) 15000 series nodes before 20060405 allow remote attackers to cause a denial of service (card reset) via (1) a "crafted" IP packet to a device with secure mode EMS-to-network-element access, aka bug ID CSCsc51390; (2) a "crafted" IP packet to a device with IP on the LAN interface, aka bug ID CSCsd04168; and (3) a "malformed" OSPF packet, aka bug ID CSCsc54558.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://secunia.com/advisories/19553http://securitytracker.com/id?1015872http://www.cisco.com/warp/public/707/cisco-sa-20060405-ons.shtmlhttp://www.osvdb.org/24435http://www.osvdb.org/24436http://www.osvdb.org/24437http://www.securityfocus.com/bid/17384http://www.vupen.com/english/advisories/2006/1256https://exchange.xforce.ibmcloud.com/vulnerabilities/25644https://exchange.xforce.ibmcloud.com/vulnerabilities/25645https://exchange.xforce.ibmcloud.com/vulnerabilities/25646http://secunia.com/advisories/19553http://securitytracker.com/id?1015872http://www.cisco.com/warp/public/707/cisco-sa-20060405-ons.shtmlhttp://www.osvdb.org/24435http://www.osvdb.org/24436http://www.osvdb.org/24437http://www.securityfocus.com/bid/17384http://www.vupen.com/english/advisories/2006/1256https://exchange.xforce.ibmcloud.com/vulnerabilities/25644https://exchange.xforce.ibmcloud.com/vulnerabilities/25645https://exchange.xforce.ibmcloud.com/vulnerabilities/25646
2006-04-07
Published