CVE-2006-1670
Control cards for Cisco Optical Networking System (ONS) 15000 series nodes before 20060405 allow remote attackers to cause a denial of service (memory exhaustion and possibly card reset) by sending an invalid response when the final ACK is expected, aka…
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (2.24%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Control cards for Cisco Optical Networking System (ONS) 15000 series nodes before 20060405 allow remote attackers to cause a denial of service (memory exhaustion and possibly card reset) by sending an invalid response when the final ACK is expected, aka bug ID CSCei45910.
- CVSS 2.0
- 7.8 HIGHAV:N/AC:L/Au:N/C:N/I:N/A:C
- EPSS
- 2.24% probability · 82th percentile
- CISA KEV
- Not listed
- Affected
- cisco/optical networking systems software · cisco/ons 15310-cl series · cisco/ons 15600 · cisco/ons 15454 mspp · cisco/ons 15454 mstp
- Source
- cve@mitre.org
References
- http://secunia.com/advisories/19553
- http://securitytracker.com/id?1015872
- http://www.cisco.com/warp/public/707/cisco-sa-20060405-ons.shtmlExploit, Patch, Vendor Advisory
- http://www.osvdb.org/24434
- http://www.securityfocus.com/bid/17384Exploit, Patch
- http://www.vupen.com/english/advisories/2006/1256
- https://exchange.xforce.ibmcloud.com/vulnerabilities/25643
- http://secunia.com/advisories/19553
- http://securitytracker.com/id?1015872
- http://www.cisco.com/warp/public/707/cisco-sa-20060405-ons.shtmlExploit, Patch, Vendor Advisory
- http://www.osvdb.org/24434
- http://www.securityfocus.com/bid/17384Exploit, Patch
- http://www.vupen.com/english/advisories/2006/1256
- https://exchange.xforce.ibmcloud.com/vulnerabilities/25643
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.