CVE-2004-1435
Multiple versions of Cisco ONS 15327, ONS 15454, and ONS 15454 SDH, including 4.6(0) and 4.6(1), 4.5(x), 4.1(0) to 4.1(3), 4.0(0) to 4.0(2), and earlier versions, allows remote attackers to cause a denial of service (control card reset) via a large…
Does this matter?
Lower severity and a low EPSS score (3.16%). Track it; it rarely justifies an emergency change on its own.
Description
Multiple versions of Cisco ONS 15327, ONS 15454, and ONS 15454 SDH, including 4.6(0) and 4.6(1), 4.5(x), 4.1(0) to 4.1(3), 4.0(0) to 4.0(2), and earlier versions, allows remote attackers to cause a denial of service (control card reset) via a large number of TCP connections with an invalid response instead of the final ACK (TCP-ACK).
- CVSS 2.0
- 5.0 MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
- EPSS
- 3.16% probability · 87th percentile
- CISA KEV
- Not listed
- Affected
- cisco/optical networking systems software
- Source
- cve@mitre.org
References
- http://secunia.com/advisories/12117
- http://www.cisco.com/warp/public/707/cisco-sa-20040721-ons.shtmlVendor Advisory
- http://www.kb.cert.org/vuls/id/277048Third Party Advisory, US Government Resource
- http://www.securityfocus.com/bid/10768
- https://exchange.xforce.ibmcloud.com/vulnerabilities/16763
- http://secunia.com/advisories/12117
- http://www.cisco.com/warp/public/707/cisco-sa-20040721-ons.shtmlVendor Advisory
- http://www.kb.cert.org/vuls/id/277048Third Party Advisory, US Government Resource
- http://www.securityfocus.com/bid/10768
- https://exchange.xforce.ibmcloud.com/vulnerabilities/16763
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.