PT-2006-2665 · Cisco · Cisco Ons 15000
Published
2006-04-07
·
Updated
2018-10-30
·
CVE-2006-1671
CVSS v2.0
5.0
Medium
| Vector | AV:N/AC:L/Au:N/C:N/I:N/A:P |
Name of the Vulnerable Software and Affected Versions:
Cisco Optical Networking System (ONS) 15000 series nodes versions prior to 20060405
Description:
The issue allows remote attackers to cause a denial of service, resulting in a card reset. This can be achieved through various means, including sending a
crafted IP packet to a device with secure mode EMS-to-network-element access, sending a crafted IP packet to a device with IP on the LAN interface, or sending a malformed OSPF packet.Recommendations:
For versions prior to 20060405, update to a version released after 20060405 to resolve the issue. As a temporary workaround, consider restricting access to the LAN interface and limiting the devices that can send IP packets to the ONS 15000 series nodes. Additionally, restricting OSPF packet traffic to trusted sources may help minimize the risk of exploitation.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Cisco Ons 15000