ID

VAR-201404-0579


CVE

CVE-2014-2142


TITLE

Cisco ONS 15454 Service operation interruption in controller card software (DoS) Vulnerabilities

Trust: 0.8

sources: JVNDB: JVNDB-2014-001972

DESCRIPTION

Cisco ONS 15454 controller cards with software 10.0 and earlier allow remote attackers to cause a denial of service (card reload) via a crafted HTTP URI, aka Bug ID CSCun06870. Cisco ONS 15454 System Software is prone to a denial-of-service vulnerability. An attacker can exploit this issue to cause the control card to reset, denying service to legitimate users. This issue is being tracked by Cisco bug ID CSCun06870. Cisco ONS 15454 is a set of optical network multi-service transmission platform of American Cisco (Cisco). The platform leverages optical transport technologies such as Resilient Packet Ring (RPR), SDH, and DWDM/CWDM to integrate Ethernet, IP, storage, and TDM services to deliver next-generation voice, data services, and more. Controller Cards is one of the control cards

Trust: 1.98

sources: NVD: CVE-2014-2142 // JVNDB: JVNDB-2014-001972 // BID: 66686 // VULHUB: VHN-70081

AFFECTED PRODUCTS

vendor:ciscomodel:ons 15454 system softwarescope:lteversion:10.0

Trust: 1.8

vendor:ciscomodel:ons 15454 system softwarescope:eqversion:9.6

Trust: 1.6

vendor:ciscomodel:ons 15454 system softwarescope:eqversion:9.4

Trust: 1.6

vendor:ciscomodel:ons 15454 system softwarescope:eqversion:9.0

Trust: 1.6

vendor:ciscomodel:ons 15454 system softwarescope:eqversion:9.2.2

Trust: 1.6

vendor:ciscomodel:ons 15454 system softwarescope:eqversion:9.2.1

Trust: 1.6

vendor:ciscomodel:ons 15454 system softwarescope:eqversion:9.3

Trust: 1.6

vendor:ciscomodel:ons 15454 system softwarescope:eqversion:9.1

Trust: 1.6

vendor:ciscomodel:ons 15454 system softwarescope:eqversion:9.2

Trust: 1.6

vendor:ciscomodel:ons 15454 system softwarescope:eqversion:9.8

Trust: 1.6

vendor:ciscomodel:ons 15454scope:eqversion:*

Trust: 1.0

vendor:ciscomodel:ons 15454scope: - version: -

Trust: 0.8

vendor:ciscomodel:ons 15454 system softwarescope:eqversion:10.0

Trust: 0.6

sources: JVNDB: JVNDB-2014-001972 // CNNVD: CNNVD-201404-182 // NVD: CVE-2014-2142

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2014-2142
value: MEDIUM

Trust: 1.0

NVD: CVE-2014-2142
value: MEDIUM

Trust: 0.8

CNNVD: CNNVD-201404-182
value: MEDIUM

Trust: 0.6

VULHUB: VHN-70081
value: MEDIUM

Trust: 0.1

nvd@nist.gov: CVE-2014-2142
severity: MEDIUM
baseScore: 5.0
vectorString: AV:N/AC:L/AU:N/C:N/I:N/A:P
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: NONE
integrityImpact: NONE
availabilityImpact: PARTIAL
exploitabilityScore: 10.0
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.8

VULHUB: VHN-70081
severity: MEDIUM
baseScore: 5.0
vectorString: AV:N/AC:L/AU:N/C:N/I:N/A:P
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: NONE
integrityImpact: NONE
availabilityImpact: PARTIAL
exploitabilityScore: 10.0
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.1

sources: VULHUB: VHN-70081 // JVNDB: JVNDB-2014-001972 // CNNVD: CNNVD-201404-182 // NVD: CVE-2014-2142

PROBLEMTYPE DATA

problemtype:NVD-CWE-noinfo

Trust: 1.0

sources: NVD: CVE-2014-2142

THREAT TYPE

remote

Trust: 0.6

sources: CNNVD: CNNVD-201404-182

TYPE

Failure to Handle Exceptional Conditions

Trust: 0.3

sources: BID: 66686

CONFIGURATIONS

sources: JVNDB: JVNDB-2014-001972

PATCH

title:Cisco ONS 15454 Controller Card Denial of Service Vulnerabilityurl:http://tools.cisco.com/security/center/content/CiscoSecurityNotice/CVE-2014-2142

Trust: 0.8

title:33679url:http://tools.cisco.com/security/center/viewAlert.x?alertId=33679

Trust: 0.8

sources: JVNDB: JVNDB-2014-001972

EXTERNAL IDS

db:NVDid:CVE-2014-2142

Trust: 2.8

db:JVNDBid:JVNDB-2014-001972

Trust: 0.8

db:CNNVDid:CNNVD-201404-182

Trust: 0.7

db:CISCOid:20140407 CISCO ONS 15454 CONTROLLER CARD DENIAL OF SERVICE VULNERABILITY

Trust: 0.6

db:SECUNIAid:57728

Trust: 0.6

db:BIDid:66686

Trust: 0.4

db:VULHUBid:VHN-70081

Trust: 0.1

sources: VULHUB: VHN-70081 // BID: 66686 // JVNDB: JVNDB-2014-001972 // CNNVD: CNNVD-201404-182 // NVD: CVE-2014-2142

REFERENCES

url:http://tools.cisco.com/security/center/content/ciscosecuritynotice/cve-2014-2142

Trust: 1.7

url:http://tools.cisco.com/security/center/viewalert.x?alertid=33679

Trust: 1.7

url:http://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2014-2142

Trust: 0.8

url:http://web.nvd.nist.gov/view/vuln/detail?vulnid=cve-2014-2142

Trust: 0.8

url:http://secunia.com/advisories/57728

Trust: 0.6

url:http://www.cisco.com/

Trust: 0.3

sources: VULHUB: VHN-70081 // BID: 66686 // JVNDB: JVNDB-2014-001972 // CNNVD: CNNVD-201404-182 // NVD: CVE-2014-2142

CREDITS

Cisco

Trust: 0.3

sources: BID: 66686

SOURCES

db:VULHUBid:VHN-70081
db:BIDid:66686
db:JVNDBid:JVNDB-2014-001972
db:CNNVDid:CNNVD-201404-182
db:NVDid:CVE-2014-2142

LAST UPDATE DATE

2024-11-23T22:13:43.938000+00:00


SOURCES UPDATE DATE

db:VULHUBid:VHN-70081date:2014-04-14T00:00:00
db:BIDid:66686date:2014-04-07T00:00:00
db:JVNDBid:JVNDB-2014-001972date:2014-04-15T00:00:00
db:CNNVDid:CNNVD-201404-182date:2014-04-16T00:00:00
db:NVDid:CVE-2014-2142date:2024-11-21T02:05:43.990

SOURCES RELEASE DATE

db:VULHUBid:VHN-70081date:2014-04-12T00:00:00
db:BIDid:66686date:2014-04-07T00:00:00
db:JVNDBid:JVNDB-2014-001972date:2014-04-15T00:00:00
db:CNNVDid:CNNVD-201404-182date:2014-04-16T00:00:00
db:NVDid:CVE-2014-2142date:2014-04-12T04:37:31.877