First published: Wed Sep 01 2004(Updated: )
Cisco ONS 15327 before 4.1(3), ONS 15454 before 4.6(1), and ONS 15454 SD before 4.1(3) allows remote attackers to cause a denial of service (reset) by not sending the ACK portion of the TCP three-way handshake and sending an invalid response instead.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Cisco Optical Networking systems software | =1.0 | |
Cisco Optical Networking systems software | =4.0\(1\) | |
Cisco Optical Networking systems software | =4.0\(2\) | |
Cisco Optical Networking systems software | =4.0.0 | |
Cisco Optical Networking systems software | =4.1\(0\) | |
Cisco Optical Networking systems software | =4.1\(1\) | |
Cisco Optical Networking systems software | =4.1\(2\) | |
Cisco Optical Networking systems software | =4.1\(3\) | |
Cisco Optical Networking systems software | =4.1.0 | |
Cisco Optical Networking systems software | =4.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2004-0307 has been classified as a denial of service vulnerability that can disrupt service on affected systems.
To address CVE-2004-0307, it is recommended to upgrade the impacted Cisco Optical Networking systems software to version 4.1(3) or higher.
CVE-2004-0307 affects Cisco ONS 15327, ONS 15454, and ONS 15454 SD prior to specified software versions.
Implementing network-level controls to filter unexpected TCP packets can help mitigate the impact of CVE-2004-0307.
Currently, there are no known workarounds for CVE-2004-0307, and upgrading the software is the best solution.