Vulnerability Name: CVE-2004-1434 (CCN-16765) Assigned: 2004-07-21 Published: 2004-07-21 Updated: 2018-10-30 Summary: Multiple versions of Cisco ONS 15327, ONS 15454, and ONS 15454 SDH, including 4.1(0) to 4.1(2), 4.5(x), 4.0(0) to 4.0(2), and earlier versions, allows remote attackers to cause a denial of service (control card reset) via malformed SNMP packets. CVSS v3 Severity: 5.3 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L )Exploitability Metrics: Attack Vector (AV): NetworkAttack Complexity (AC): LowPrivileges Required (PR): NoneUser Interaction (UI): NoneScope: Scope (S): UnchangedImpact Metrics: Confidentiality (C): NoneIntegrity (I): NoneAvailibility (A): Low
CVSS v2 Severity: 5.0 Medium (CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P )Exploitability Metrics: Access Vector (AV): NetworkAccess Complexity (AC): LowAuthentication (Au): NoneImpact Metrics: Confidentiality (C): NoneIntegrity (I): NoneAvailibility (A): Partial
5.0 Medium (CCN CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P )Exploitability Metrics: Access Vector (AV): NetworkAccess Complexity (AC): LowAthentication (Au): NoneImpact Metrics: Confidentiality (C): NoneIntegrity (I): NoneAvailibility (A): Partial
Vulnerability Type: CWE-Other Vulnerability Consequences: Denial of Service References: Source: MITRE Type: CNACVE-2004-1434 Source: CCN Type: SA12117Cisco ONS 15000 Multiple Denial of Service Vulnerabilities Source: SECUNIA Type: UNKNOWN12117 Source: CCN Type: cisco-sa-20040721-onsCisco Security Advisory: Cisco ONS 15327, ONS 15454, ONS 15454 SDH, and ONS 15600 Malformed Packet Vulnerabilities Source: CISCO Type: Vendor Advisory20040721 Cisco ONS 15327, ONS 15454, ONS 15454 SDH, and ONS 15600 Malformed Packet Vulnerabilities Source: CCN Type: US-CERT VU#548968Multiple Cisco ONS control cards fail to properly handle malformed SNMP packets Source: CERT-VN Type: Exploit, US Government ResourceVU#548968 Source: CCN Type: OSVDB ID: 8154Cisco ONS 15000 Series Malformed SNMP DoS Source: BID Type: UNKNOWN10768 Source: CCN Type: BID-10768Cisco ONS Multiple Vulnerabilities Source: XF Type: UNKNOWNcisco-ons-snmp-dos(16765) Source: XF Type: UNKNOWNcisco-ons-snmp-dos(16765) Vulnerable Configuration: Configuration 1 :cpe:/a:cisco:optical_networking_systems_software:1.0:*:*:*:*:*:*:* OR cpe:/a:cisco:optical_networking_systems_software:1.1:*:*:*:*:*:*:* OR cpe:/a:cisco:optical_networking_systems_software:1.1(0):*:*:*:*:*:*:* OR cpe:/a:cisco:optical_networking_systems_software:1.1(1):*:*:*:*:*:*:* OR cpe:/a:cisco:optical_networking_systems_software:1.3(0):*:*:*:*:*:*:* OR cpe:/a:cisco:optical_networking_systems_software:2.3(5):*:*:*:*:*:*:* OR cpe:/a:cisco:optical_networking_systems_software:3.0:*:*:*:*:*:*:* OR cpe:/a:cisco:optical_networking_systems_software:3.1.0:*:*:*:*:*:*:* OR cpe:/a:cisco:optical_networking_systems_software:3.2:*:*:*:*:*:*:* OR cpe:/a:cisco:optical_networking_systems_software:3.2.0:*:*:*:*:*:*:* OR cpe:/a:cisco:optical_networking_systems_software:3.3.0:*:*:*:*:*:*:* OR cpe:/a:cisco:optical_networking_systems_software:3.4.0:*:*:*:*:*:*:* OR cpe:/a:cisco:optical_networking_systems_software:4.0(0):*:*:*:*:*:*:* OR cpe:/a:cisco:optical_networking_systems_software:4.0(1):*:*:*:*:*:*:* OR cpe:/a:cisco:optical_networking_systems_software:4.0(2):*:*:*:*:*:*:* OR cpe:/a:cisco:optical_networking_systems_software:4.0.0:*:*:*:*:*:*:* OR cpe:/a:cisco:optical_networking_systems_software:4.1(0):*:*:*:*:*:*:* OR cpe:/a:cisco:optical_networking_systems_software:4.1(1):*:*:*:*:*:*:* OR cpe:/a:cisco:optical_networking_systems_software:4.1(2):*:*:*:*:*:*:* OR cpe:/a:cisco:optical_networking_systems_software:4.1(3):*:*:*:*:*:*:* OR cpe:/a:cisco:optical_networking_systems_software:4.5:*:*:*:*:*:*:* OR cpe:/a:cisco:optical_networking_systems_software:4.6(0):*:*:*:*:*:*:* OR cpe:/a:cisco:optical_networking_systems_software:4.6(1):*:*:*:*:*:*:* Denotes that component is vulnerable BACK
cisco optical networking systems software 1.0
cisco optical networking systems software 1.1
cisco optical networking systems software 1.1(0)
cisco optical networking systems software 1.1(1)
cisco optical networking systems software 1.3(0)
cisco optical networking systems software 2.3(5)
cisco optical networking systems software 3.0
cisco optical networking systems software 3.1.0
cisco optical networking systems software 3.2
cisco optical networking systems software 3.2.0
cisco optical networking systems software 3.3.0
cisco optical networking systems software 3.4.0
cisco optical networking systems software 4.0(0)
cisco optical networking systems software 4.0(1)
cisco optical networking systems software 4.0(2)
cisco optical networking systems software 4.0.0
cisco optical networking systems software 4.1(0)
cisco optical networking systems software 4.1(1)
cisco optical networking systems software 4.1(2)
cisco optical networking systems software 4.1(3)
cisco optical networking systems software 4.5
cisco optical networking systems software 4.6(0)
cisco optical networking systems software 4.6(1)