|
Cisco ONS 15000 Multiple Denial of Service Vulnerabilities
|
|
Secunia Advisory:
|
SA12117
|
|
|
Release Date:
|
2004-07-21
|
|
Last Update:
|
2005-02-15
|
|
Popularity:
|
8,622 views
|
|
|
Critical:
|
 Less critical
|
|
Impact:
|
Security Bypass DoS
|
|
Where:
|
From local network
|
|
Solution Status:
|
Vendor Patch
|
|
| OS: | Cisco ONS 15000 Series
|
|
|
Secunia CVSS-2 Score:
|
Available in Secunia business solutions
|
|
|
Subscribe:
|
Instant alerts on relevant vulnerabilities
|
|
| Advisory Content (Page 1 of 3) | [ 1 ] [ 2 ] [ 3 ] | |
|
Description: The vendor has reported several vulnerabilities in Cisco ONS 15000 based products, allowing malicious people to cause a Denial of Service or bypass authentication.
1) The XTC, TCC/TCC+/TCC2 and TCCi/TCC2 control cards fail to handle multiple malformed IP packets. This may allow malicious people to cause the control cards to reset.
2) The XTC, TCC/TCC+/TCC2 and TCCi/TCC2 control cards fail to handle multiple malformed ICMP packets. This may allow malicious people to cause the control cards to reset.
3) The XTC, TCC/TCC+/TCC2, TCCi/TCC2 and TSC control cards fail to handle multiple malformed TCP packets. This may allow malicious people to cause the control cards to reset.
4) The XTC, TCC/TCC+/TCC2 and TCCi/TCC2 control cards fail to handle TCP sequences which don't send the final ACK but send an invalid reply instead. This may allow malicious people to cause the control cards to reset.
5) The XTC, TCC/TCC+/TCC2, TCCi/TCC2 and TSC control cards fail to handle multiple malformed UDP packets. This may allow malicious people to cause the control cards to reset.
6) The XTC, TCC/TCC+/TCC2 and TCCi/TCC2 control cards fail to handle multiple malformed SNMP packets. This may allow malicious people to cause the control cards to reset.
7) The TL1 login interface allows malicious people to authenticate by supplying any string longer than 10 characters as a password for any account with an empty password.
According to the vendor the above issues only affect the control cards, however it also causes timing problems for synchronous data channels. Asynchronous data channels are not affected.
For detailed information about vulnerable versions see vendor advisory:
http://www.cisco.com/warp/public/707/cisco-sa-20040721-ons.shtml
Change Page: [ 1 ] [ 2 ] [ 3 ]
|
|
|
Track this Secunia Advisory
|
Customers of the Secunia Vulnerability Intelligence solutions will automatically receive updates when new information regarding this advisory is released.
Read more about our Vulnerability Intelligence solutions and what they can do for you and your company.
|
|
|
About this Secunia Advisory
|
Please note: The information that this Secunia Advisory is based on comes from a third party unless stated otherwise.
Secunia collects, validates, and verifies all vulnerability reports issued by security research groups, vendors, and others.
|
|
|
27th Nov, 2009
|
New advisories:
|
8 |
|
New vulnerabilities:
|
15 |
|
Updated advisories:
|
11 |
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
26th Nov, 2009
|
New advisories:
|
15 |
|
New vulnerabilities:
|
37 |
|
Updated advisories:
|
48 |
|
|
|
|
|
|
|
Solutions | More...
|
|