First published: Wed Sep 01 2004(Updated: )
Cisco ONS 15327 before 4.1(3), ONS 15454 before 4.6(1), ONS 15454 SD before 4.1(3), and Cisco ONS 15600 before 1.3(0) enable TFTP service on UDP port 69 by default, which allows remote attackers to GET or PUT ONS system files on the current active TCC in the /flash0 or /flash1 directories.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Cisco Optical Networking systems software | =4.0.0 | |
Cisco Optical Networking systems software | =1.0 | |
Cisco Optical Networking systems software | =4.1\(2\) | |
Cisco Optical Networking systems software | =4.1\(3\) | |
Cisco Optical Networking systems software | =4.0\(2\) | |
Cisco Optical Networking systems software | =4.1.0 | |
Cisco Optical Networking systems software | =4.1\(0\) | |
Cisco Optical Networking systems software | =4.1\(1\) | |
Cisco Optical Networking systems software | =4.0\(1\) | |
Cisco Optical Networking systems software | =4.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2004-0306 is considered a critical vulnerability due to the risk of unauthorized access to system files.
To mitigate CVE-2004-0306, disable the TFTP service on UDP port 69 in your Cisco Optical Networking systems.
CVE-2004-0306 affects Cisco ONS 15327, ONS 15454, ONS 15454 SD, and ONS 15600 devices running specific vulnerable versions.
Yes, patches are available for affected Cisco Optical Networking software versions to address CVE-2004-0306.
CVE-2004-0306 can allow remote attackers to read or modify critical system files, severely compromising network security.