Vulnerability Name: CVE-2004-1435 (CCN-16763) Assigned: 2004-07-21 Published: 2004-07-21 Updated: 2018-10-30 Summary: Multiple versions of Cisco ONS 15327, ONS 15454, and ONS 15454 SDH, including 4.6(0) and 4.6(1), 4.5(x), 4.1(0) to 4.1(3), 4.0(0) to 4.0(2), and earlier versions, allows remote attackers to cause a denial of service (control card reset) via a large number of TCP connections with an invalid response instead of the final ACK (TCP-ACK). CVSS v3 Severity: 5.3 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L )Exploitability Metrics: Attack Vector (AV): NetworkAttack Complexity (AC): LowPrivileges Required (PR): NoneUser Interaction (UI): NoneScope: Scope (S): UnchangedImpact Metrics: Confidentiality (C): NoneIntegrity (I): NoneAvailibility (A): Low
CVSS v2 Severity: 5.0 Medium (CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P )Exploitability Metrics: Access Vector (AV): NetworkAccess Complexity (AC): LowAuthentication (Au): NoneImpact Metrics: Confidentiality (C): NoneIntegrity (I): NoneAvailibility (A): Partial
5.0 Medium (CCN CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P )Exploitability Metrics: Access Vector (AV): NetworkAccess Complexity (AC): LowAthentication (Au): NoneImpact Metrics: Confidentiality (C): NoneIntegrity (I): NoneAvailibility (A): Partial
Vulnerability Type: CWE-Other Vulnerability Consequences: Denial of Service References: Source: MITRE Type: CNACVE-2004-1435 Source: CCN Type: SA12117Cisco ONS 15000 Multiple Denial of Service Vulnerabilities Source: SECUNIA Type: UNKNOWN12117 Source: CCN Type: cisco-sa-20040721-onsCisco Security Advisory: Cisco ONS 15327, ONS 15454, ONS 15454 SDH, and ONS 15600 Malformed Packet Vulnerabilities Source: CISCO Type: Vendor Advisory20040721 Cisco ONS 15327, ONS 15454, ONS 15454 SDH, and ONS 15600 Malformed Packet Vulnerabilities Source: CCN Type: US-CERT VU#277048Multiple Cisco ONS control cards fail to properly handle invalid TCP responses Source: CERT-VN Type: Third Party Advisory, US Government ResourceVU#277048 Source: CCN Type: OSVDB ID: 8152Cisco ONS 15000 Series Last-ACK DoS Source: BID Type: UNKNOWN10768 Source: CCN Type: BID-10768Cisco ONS Multiple Vulnerabilities Source: XF Type: UNKNOWNcisco-ons-tcp-ack-dos(16763) Source: XF Type: UNKNOWNcisco-ons-tcp-ack-dos(16763) Vulnerable Configuration: Configuration 1 :cpe:/a:cisco:optical_networking_systems_software:1.0:*:*:*:*:*:*:* OR cpe:/a:cisco:optical_networking_systems_software:1.1:*:*:*:*:*:*:* OR cpe:/a:cisco:optical_networking_systems_software:1.1(0):*:*:*:*:*:*:* OR cpe:/a:cisco:optical_networking_systems_software:1.1(1):*:*:*:*:*:*:* OR cpe:/a:cisco:optical_networking_systems_software:1.3(0):*:*:*:*:*:*:* OR cpe:/a:cisco:optical_networking_systems_software:2.3(5):*:*:*:*:*:*:* OR cpe:/a:cisco:optical_networking_systems_software:3.0:*:*:*:*:*:*:* OR cpe:/a:cisco:optical_networking_systems_software:3.1.0:*:*:*:*:*:*:* OR cpe:/a:cisco:optical_networking_systems_software:3.2:*:*:*:*:*:*:* OR cpe:/a:cisco:optical_networking_systems_software:3.2.0:*:*:*:*:*:*:* OR cpe:/a:cisco:optical_networking_systems_software:3.3.0:*:*:*:*:*:*:* OR cpe:/a:cisco:optical_networking_systems_software:3.4.0:*:*:*:*:*:*:* OR cpe:/a:cisco:optical_networking_systems_software:4.0(0):*:*:*:*:*:*:* OR cpe:/a:cisco:optical_networking_systems_software:4.0(1):*:*:*:*:*:*:* OR cpe:/a:cisco:optical_networking_systems_software:4.0(2):*:*:*:*:*:*:* OR cpe:/a:cisco:optical_networking_systems_software:4.0.0:*:*:*:*:*:*:* OR cpe:/a:cisco:optical_networking_systems_software:4.1(0):*:*:*:*:*:*:* OR cpe:/a:cisco:optical_networking_systems_software:4.1(1):*:*:*:*:*:*:* OR cpe:/a:cisco:optical_networking_systems_software:4.1(2):*:*:*:*:*:*:* OR cpe:/a:cisco:optical_networking_systems_software:4.1(3):*:*:*:*:*:*:* OR cpe:/a:cisco:optical_networking_systems_software:4.5:*:*:*:*:*:*:* OR cpe:/a:cisco:optical_networking_systems_software:4.6(0):*:*:*:*:*:*:* OR cpe:/a:cisco:optical_networking_systems_software:4.6(1):*:*:*:*:*:*:* Denotes that component is vulnerable BACK
cisco optical networking systems software 1.0
cisco optical networking systems software 1.1
cisco optical networking systems software 1.1(0)
cisco optical networking systems software 1.1(1)
cisco optical networking systems software 1.3(0)
cisco optical networking systems software 2.3(5)
cisco optical networking systems software 3.0
cisco optical networking systems software 3.1.0
cisco optical networking systems software 3.2
cisco optical networking systems software 3.2.0
cisco optical networking systems software 3.3.0
cisco optical networking systems software 3.4.0
cisco optical networking systems software 4.0(0)
cisco optical networking systems software 4.0(1)
cisco optical networking systems software 4.0(2)
cisco optical networking systems software 4.0.0
cisco optical networking systems software 4.1(0)
cisco optical networking systems software 4.1(1)
cisco optical networking systems software 4.1(2)
cisco optical networking systems software 4.1(3)
cisco optical networking systems software 4.5
cisco optical networking systems software 4.6(0)
cisco optical networking systems software 4.6(1)