PT-2009-1210 · Cisco · Cisco Ons 15310-Ma+5
Published
2009-01-16
·
Updated
2017-08-08
·
CVE-2008-3818
CVSS v2.0
7.8
High
| Vector | AV:N/AC:L/Au:N/C:N/I:N/A:C |
Name of the Vulnerable Software and Affected Versions
Cisco ONS 15310-CL, 15310-MA, 15327, 15454, 15454 SDH, and 15600 versions 7.0.2 through 7.0.6
Cisco ONS 15310-CL, 15310-MA, 15327, 15454, 15454 SDH, and 15600 version 7.2.2
Cisco ONS 15310-CL, 15310-MA, 15327, 15454, 15454 SDH, and 15600 versions 8.0.x
Cisco ONS 15310-CL, 15310-MA, 15327, 15454, 15454 SDH, and 15600 version 8.5.1
Cisco ONS 15310-CL, 15310-MA, 15327, 15454, 15454 SDH, and 15600 version 8.5.2
Description
The issue allows remote attackers to cause a denial of service via a crafted TCP session, resulting in a control-card reset.
Recommendations
For versions 7.0.2 through 7.0.6, consider applying configuration changes to restrict access to the control card.
For version 7.2.2, restrict access to the control card to minimize the risk of exploitation.
For versions 8.0.x, avoid using the affected TCP session functionality until the issue is resolved.
For version 8.5.1, consider disabling the control-card reset functionality as a temporary workaround.
For version 8.5.2, restrict access to the control card to prevent denial of service attacks.
At the moment, there is no information about a newer version that contains a fix for this issue.
Fix
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Cisco Ons 15310-Cl
Cisco Ons 15310-Ma
Cisco Ons 15327
Cisco Ons 15454
Cisco Ons 15454 Sdh
Cisco Ons 15600