PT-2006-2665 · Cisco · Cisco Ons 15000

Published

2006-04-07

·

Updated

2018-10-30

·

CVE-2006-1671

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:N/I:N/A:P
Name of the Vulnerable Software and Affected Versions: Cisco Optical Networking System (ONS) 15000 series nodes versions prior to 20060405
Description: The issue allows remote attackers to cause a denial of service, resulting in a card reset. This can be achieved through various means, including sending a crafted IP packet to a device with secure mode EMS-to-network-element access, sending a crafted IP packet to a device with IP on the LAN interface, or sending a malformed OSPF packet.
Recommendations: For versions prior to 20060405, update to a version released after 20060405 to resolve the issue. As a temporary workaround, consider restricting access to the LAN interface and limiting the devices that can send IP packets to the ONS 15000 series nodes. Additionally, restricting OSPF packet traffic to trusted sources may help minimize the risk of exploitation.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2006-1671

Affected Products

Cisco Ons 15000