CVE-2006-1672
published 2006-04-07CVE-2006-1672: The installation of Cisco Transport Controller (CTC) for Cisco Optical Networking System (ONS) 15000 series nodes adds a Java policy file entry with a wildcard…
PriorityP341high7.5CVSS 2.0
AVNACLAuNCPIPAP
EPSS
4.02%
89.4th percentile
The installation of Cisco Transport Controller (CTC) for Cisco Optical Networking System (ONS) 15000 series nodes adds a Java policy file entry with a wildcard that grants the java.security.AllPermission permission to any http URL containing "fs/LAUNCHER.jar", which allows remote attackers to execute arbitrary code on a CTC workstation, aka bug ID CSCea25049.
Affected
24 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | ons_15310-cl_series | — | — |
| cisco | ons_15600 | — | — |
| cisco | optical_networking_system_15000_series_and_cisco_transport_controller | — | — |
| cisco | optical_networking_systems_software | — | — |
| cisco | optical_networking_systems_software | — | — |
| cisco | optical_networking_systems_software | — | — |
| cisco | optical_networking_systems_software | — | — |
| cisco | optical_networking_systems_software | — | — |
| cisco | optical_networking_systems_software | — | — |
| cisco | optical_networking_systems_software | — | — |
| cisco | optical_networking_systems_software | — | — |
| cisco | optical_networking_systems_software | — | — |
| cisco | optical_networking_systems_software | — | — |
| cisco | optical_networking_systems_software | — | — |
| cisco | optical_networking_systems_software | — | — |
| cisco | optical_networking_systems_software | — | — |
| cisco | optical_networking_systems_software | — | — |
| cisco | optical_networking_systems_software | — | — |
| cisco | optical_networking_systems_software | — | — |
| cisco | optical_networking_systems_software | — | — |
| cisco | optical_networking_systems_software | — | — |
| cisco | optical_networking_systems_software | — | — |
| cisco | optical_networking_systems_software | — | — |
| cisco | transport_controller | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-34wc-p67w-xmgr: The installation of Cisco Transport Controller (CTC) for Cisco Optical Networking System (ONS) 15000 series nodes adds a Java policy file entry with a
ghsa_unreviewed·2022-05-01
CVE-2006-1672 [HIGH] GHSA-34wc-p67w-xmgr: The installation of Cisco Transport Controller (CTC) for Cisco Optical Networking System (ONS) 15000 series nodes adds a Java policy file entry with a
The installation of Cisco Transport Controller (CTC) for Cisco Optical Networking System (ONS) 15000 series nodes adds a Java policy file entry with a wildcard that grants the java.security.AllPermission permission to any http URL containing "fs/LAUNCHER.jar", which allows remote attackers to execute arbitrary code on a CTC workstation, aka bug ID CSCea25049.
Cisco
Cisco Optical Networking System 15000 Series and Cisco Transport Controller Vulnerabilities
vendor_cisco·2006-04-05
CVE-2006-1670 CWE-399 Cisco Optical Networking System 15000 Series and Cisco Transport Controller Vulnerabilities
Cisco Optical Networking System 15000 Series and Cisco Transport Controller Vulnerabilities
Multiple vulnerabilities exist in the Cisco Optical Networking System
(ONS) 15310 Multi-service Provisioning Platforms (MSPP), ONS 15327 MSPP, ONS
15454 MSPP, ONS 15454 Multi-service Transport Platform (MSTP) and the ONS 15600
MSPP. These vulnerabilities will affect Optical nodes that have the Common
Control Cards connected to a Data Communications Network (DCN) and are enabled
for Internet Protocol Version 4 (IP). Successful exploitation of these
vulnerabilities will result in a denial of service (DoS) of the Common Control
Cards.
A separate vulnerability exists within the Cisco Transport Controller
(CTC) applet launcher which may allow execution of arbitrary code on the CTC
workstation. This so
Cisco
Cisco Optical Networking System 15000 Series and Cisco Transport Controller Vulnerabilities
vendor_cisco
CVE-2006-1672 Cisco Optical Networking System 15000 Series and Cisco Transport Controller Vulnerabilities
CVE-2006-1672: Cisco Optical Networking System 15000 Series and Cisco Transport Controller Vulnerabilities
Multiple vulnerabilities exist in the Cisco Optical Networking System (ONS) 15310 Multi-service Provisioning Platforms (MSPP), ONS 15327 MSPP, ONS 15454 MSPP, ONS 15454 Multi-service Transport Platform (MSTP) and the ONS 15600 MSPP. These vulnerabilities will affect Optical nodes that have the Common Control Cards connected to a Data Communications Network (DCN) and are enabled for Internet Protocol Version 4 (IP). Successful exploitation of these vulnerabilities will result in a denial of service (DoS) of the Common Control Cards. A separate vulnerability exists within the Cisco Transport Controller (CTC) applet launcher which may allow execution of arbitrary code on the CTC workstat
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://secunia.com/advisories/19553http://securitytracker.com/id?1015871http://www.cisco.com/warp/public/707/cisco-sa-20060405-ons.shtmlhttp://www.osvdb.org/24438http://www.securityfocus.com/bid/17384http://www.vupen.com/english/advisories/2006/1256https://exchange.xforce.ibmcloud.com/vulnerabilities/25647http://secunia.com/advisories/19553http://securitytracker.com/id?1015871http://www.cisco.com/warp/public/707/cisco-sa-20060405-ons.shtmlhttp://www.osvdb.org/24438http://www.securityfocus.com/bid/17384http://www.vupen.com/english/advisories/2006/1256https://exchange.xforce.ibmcloud.com/vulnerabilities/25647
2006-04-07
Published