ID

VAR-200305-0082


TITLE

Cisco Optical Transport Platform illegal telnet request remote denial of service vulnerability

Trust: 0.6

sources: CNVD: CNVD-2003-1215

DESCRIPTION

The Cisco ONS 15454, ONS 15327, ONS 15454 SDH, and ONS 15600 hardware are managed by TCC+, XTC, TCCi, and TSC control cards, which are typically used in internal customer environments to connect to the external Internet. The telnet service of the Cisco Optical Transport Platform system handles illegal requests incorrectly. A remote attacker can exploit this vulnerability to perform a denial of service attack on the device, which can cause network interruption. By submitting an illegal telnet request, an attacker can cause a TCC+, XTC, TCCi, and TSC control card to be reset. Repeating an illegal request can cause the device to interrupt normal communication and generate a denial of service. This vulnerability was reproduced by the Nessus scanner, CISCO BUG number: CSCdz83519

Trust: 0.81

sources: CNVD: CNVD-2003-1215 // BID: 7481

IOT TAXONOMY

category:['Network device']sub_category: -

Trust: 0.6

sources: CNVD: CNVD-2003-1215

AFFECTED PRODUCTS

vendor:ciscomodel:onsscope:eqversion:156001.0

Trust: 0.9

vendor:ciscomodel:ons 15454sdhscope:eqversion:3.1

Trust: 0.9

vendor:ciscomodel:ons 15454sdhscope:eqversion:3.2

Trust: 0.9

vendor:ciscomodel:ons 15454sdhscope:eqversion:3.3

Trust: 0.9

vendor:ciscomodel:ons 15454sdhscope:eqversion:3.4

Trust: 0.9

vendor:ciscomodel:onsscope:eqversion:153273.0

Trust: 0.9

vendor:ciscomodel:onsscope:eqversion:153273.1

Trust: 0.9

vendor:ciscomodel:onsscope:eqversion:153273.2

Trust: 0.9

vendor:ciscomodel:onsscope:eqversion:153273.3

Trust: 0.9

vendor:ciscomodel:onsscope:eqversion:153273.4

Trust: 0.9

vendor:ciscomodel:ons optical transport platformscope:eqversion:154544.0(1)

Trust: 0.3

vendor:ciscomodel:ons optical transport platformscope:eqversion:154543.4

Trust: 0.3

vendor:ciscomodel:ons optical transport platformscope:eqversion:154543.3

Trust: 0.3

vendor:ciscomodel:ons optical transport platformscope:eqversion:154543.2.0

Trust: 0.3

vendor:ciscomodel:ons optical transport platformscope:eqversion:154543.1.0

Trust: 0.3

vendor:ciscomodel:ons optical transport platformscope:eqversion:154543.0

Trust: 0.3

vendor:ciscomodel:onsscope:neversion:156001.1

Trust: 0.3

vendor:ciscomodel:ons 15454sdhscope:neversion:4.0

Trust: 0.3

vendor:ciscomodel:ons optical transport platformscope:neversion:154544.0

Trust: 0.3

vendor:ciscomodel:onsscope:neversion:153274.0

Trust: 0.3

sources: CNVD: CNVD-2003-1215 // BID: 7481

CVSS

SEVERITY

CVSSV2

CVSSV3

CNVD: CNVD-2003-1215
value: MEDIUM

Trust: 0.6

CNVD: CNVD-2003-1215
severity: MEDIUM
baseScore: 5.0
vectorString: AV:N/AC:L/AU:N/C:N/I:N/A:P
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: NONE
integrityImpact: NONE
availabilityImpact: PARTIAL
exploitabilityScore: 10.0
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.6

sources: CNVD: CNVD-2003-1215

THREAT TYPE

network

Trust: 0.3

sources: BID: 7481

TYPE

Failure to Handle Exceptional Conditions

Trust: 0.3

sources: BID: 7481

PATCH

title:Cisco Optical Transport Platform illegal telnet request for remote denial of service vulnerability patchurl:https://www.cnvd.org.cn/patchinfo/show/42213

Trust: 0.6

sources: CNVD: CNVD-2003-1215

EXTERNAL IDS

db:BIDid:7481

Trust: 0.9

db:CNVDid:CNVD-2003-1215

Trust: 0.6

sources: CNVD: CNVD-2003-1215 // BID: 7481

REFERENCES

url:http://www.cisco.com/warp/public/707/cisco-sa-20030501-ons.shtml

Trust: 0.6

url:/archive/1/320182

Trust: 0.3

sources: CNVD: CNVD-2003-1215 // BID: 7481

CREDITS

This issue was announced by the vendor.

Trust: 0.3

sources: BID: 7481

SOURCES

db:CNVDid:CNVD-2003-1215
db:BIDid:7481

LAST UPDATE DATE

2022-05-17T02:05:38.270000+00:00


SOURCES UPDATE DATE

db:CNVDid:CNVD-2003-1215date:2014-01-20T00:00:00
db:BIDid:7481date:2003-05-01T00:00:00

SOURCES RELEASE DATE

db:CNVDid:CNVD-2003-1215date:2003-05-01T00:00:00
db:BIDid:7481date:2003-05-01T00:00:00