PT-2009-1210 · Cisco · Cisco Ons 15310-Ma+5

Published

2009-01-16

·

Updated

2017-08-08

·

CVE-2008-3818

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions Cisco ONS 15310-CL, 15310-MA, 15327, 15454, 15454 SDH, and 15600 versions 7.0.2 through 7.0.6 Cisco ONS 15310-CL, 15310-MA, 15327, 15454, 15454 SDH, and 15600 version 7.2.2 Cisco ONS 15310-CL, 15310-MA, 15327, 15454, 15454 SDH, and 15600 versions 8.0.x Cisco ONS 15310-CL, 15310-MA, 15327, 15454, 15454 SDH, and 15600 version 8.5.1 Cisco ONS 15310-CL, 15310-MA, 15327, 15454, 15454 SDH, and 15600 version 8.5.2
Description The issue allows remote attackers to cause a denial of service via a crafted TCP session, resulting in a control-card reset.
Recommendations For versions 7.0.2 through 7.0.6, consider applying configuration changes to restrict access to the control card. For version 7.2.2, restrict access to the control card to minimize the risk of exploitation. For versions 8.0.x, avoid using the affected TCP session functionality until the issue is resolved. For version 8.5.1, consider disabling the control-card reset functionality as a temporary workaround. For version 8.5.2, restrict access to the control card to prevent denial of service attacks. At the moment, there is no information about a newer version that contains a fix for this issue.

Fix

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2008-3818

Affected Products

Cisco Ons 15310-Cl
Cisco Ons 15310-Ma
Cisco Ons 15327
Cisco Ons 15454
Cisco Ons 15454 Sdh
Cisco Ons 15600